From 8d7e5a53fdefaa0681342ab2e16d3296d1472124 Mon Sep 17 00:00:00 2001 From: Jason Ross Date: Thu, 16 Oct 2025 12:39:21 -0500 Subject: [PATCH] creating reproducible build images --- .github/workflows/release.yml | 22 ++++----- CLAUDE.md | 3 +- scripts/docker/Dockerfile.arch | 81 ++++++++++++++++++++++++++++++++ scripts/docker/Dockerfile.debian | 81 ++++++++++++++++++++++++++++++++ scripts/docker/Dockerfile.rhel | 2 +- 5 files changed, 176 insertions(+), 13 deletions(-) create mode 100644 scripts/docker/Dockerfile.arch create mode 100644 scripts/docker/Dockerfile.debian diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 941aee7..8700e78 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -164,8 +164,8 @@ jobs: echo "pr_number=$PR_NUMBER" >> $GITHUB_OUTPUT echo "Created PR #$PR_NUMBER: $PR_URL" - # Enable auto-merge (squash) - if ! gh pr merge "$PR_NUMBER" --auto --squash --repo ${{ github.repository }}; then + # Enable auto-merge (rebase) + if ! gh pr merge "$PR_NUMBER" --auto --rebase --repo ${{ github.repository }}; then echo "::error::Failed to enable auto-merge for PR #$PR_NUMBER" exit 1 fi @@ -341,13 +341,13 @@ jobs: echo "Commit status: state=$STATE, checks=$TOTAL_COUNT (${ELAPSED}s elapsed)" - if [ "$STATE" = "success" ]; then + if [ "$STATE" = "failure" ] || [ "$STATE" = "error" ]; then + echo "::error::Status checks failed on commit $MERGE_COMMIT" + gh api "repos/${{ github.repository }}/commits/${MERGE_COMMIT}/status" --jq '.statuses[] | select(.state == "failure" or .state == "error") | "- " + .context + ": " + .state' + exit 1 + elif [ "$STATE" = "success" ]; then echo "✓ All status checks passed on main branch" exit 0 - elif [ "$STATE" = "failure" ] || [ "$STATE" = "error" ]; then - echo "::error::Status checks failed on commit $MERGE_COMMIT" - gh api "repos/${{ github.repository }}/commits/${MERGE_COMMIT}/status" --jq '.statuses[] | select(.state == "failure" or .state == "error") | "- " + .context + ": " + .state' - exit 1 fi sleep $SLEEP_INTERVAL @@ -356,12 +356,12 @@ jobs: # If we get here, treat as success if no checks were registered if [ "$TOTAL_COUNT" -eq 0 ]; then - echo "⚠ No status checks found for commit, proceeding..." - exit 0 + echo "⚠ No status checks found for commit. Investigate." + exit 1 fi - echo "::warning::Status checks still pending after ${MAX_WAIT}s, proceeding with caution..." - exit 0 + echo "::warning::Status checks still pending after ${MAX_WAIT}s, ending workflow. Investigate status checks" + exit 1 - name: Handle status check failures with rollback if: failure() && steps.check-status.outcome == 'failure' diff --git a/CLAUDE.md b/CLAUDE.md index ba3ffaa..3d16f89 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -133,10 +133,11 @@ The project uses GitHub Actions for multi-platform builds (`.github/workflows/re - Do not recreate deleted files - Do not change user-facing text unless asked - Always run the application to test if it will run and have it run successfully before declaring an iteration complete +- Never use the squash merge strategy unless specifically instructed to do so ## Notes -- **ADB Binaries**: Stored in `src/platform-tools/` - do not modify or delete +- **ADB Binaries**: Stored in `src/platform-tools/` - do not modify or delete unless explictly instructed to - **Python Version**: Requires Python 3.12 (< 3.13) - **Package Mode**: Poetry is configured with `package-mode = false` - **License**: First-run license agreement required on Windows diff --git a/scripts/docker/Dockerfile.arch b/scripts/docker/Dockerfile.arch new file mode 100644 index 0000000..54d9938 --- /dev/null +++ b/scripts/docker/Dockerfile.arch @@ -0,0 +1,81 @@ +# Dockerfile for Arch Linux build environment +# Automates all setup steps from the build-arch workflow job +# +# Usage: +# docker build -f scripts/docker/Dockerfile.arch -t android-file-handler-arch-builder . +# docker run -v $(pwd):/workspace -w /workspace android-file-handler-arch-builder + +# Use latest Arch Linux base image (rolling release) +# For reproducibility, pin to a specific date tag like: archlinux:base-20251016 +FROM archlinux:latest + +# Set build argument for fpm version (can be overridden at build time) +ARG FPM_VERSION=1.16.0 + +# Install system dependencies (Arch) including Python build dependencies +RUN pacman -Syu --noconfirm && \ + pacman -S --noconfirm \ + ruby \ + base-devel \ + curl \ + git \ + tar \ + ca-certificates \ + tk \ + tcl \ + libx11 \ + libxext \ + libxrender \ + libxcb \ + gcc \ + make \ + zlib \ + bzip2 \ + readline \ + sqlite \ + openssl \ + libffi \ + wget \ + xz \ + patch && \ + pacman -Scc --noconfirm + +# Install erb gem (required for fpm on Arch) +RUN gem install --no-document erb + +# Install fpm system-wide and pin version so fpm will be in /usr/bin +RUN gem install --no-document -v "${FPM_VERSION}" fpm --bindir /usr/bin + +# Install pyenv +ENV PYENV_ROOT="/root/.pyenv" +ENV PATH="$PYENV_ROOT/bin:$PATH" + +RUN git clone https://github.com/pyenv/pyenv.git /root/.pyenv + +# Install Python 3.12 via pyenv +RUN eval "$(pyenv init -)" && \ + pyenv install 3.12.0 && \ + pyenv global 3.12.0 && \ + pyenv rehash + +# Update PATH to include pyenv shims +ENV PATH="/root/.pyenv/shims:$PATH" + +# Install Poetry +RUN curl -sSL https://install.python-poetry.org | python3 - --yes + +# Add Poetry to PATH +ENV PATH="/root/.local/bin:$PATH" + +# Verify Poetry installation +RUN poetry --version + +# Set working directory +WORKDIR /workspace + +# Set environment variables for build +ENV CI_CD=true +ENV DISTRO_TYPE=arch + +# Default command runs the build script +CMD ["sh", "-c", "poetry install --no-interaction && poetry run python scripts/build_package_linux.py"] diff --git a/scripts/docker/Dockerfile.debian b/scripts/docker/Dockerfile.debian new file mode 100644 index 0000000..fa640e5 --- /dev/null +++ b/scripts/docker/Dockerfile.debian @@ -0,0 +1,81 @@ +# Dockerfile for Debian build environment +# Automates all setup steps from the build-debian workflow job +# +# Usage: +# docker build -f scripts/docker/Dockerfile.debian -t android-file-handler-debian-builder . +# docker run -v $(pwd):/workspace -w /workspace android-file-handler-debian-builder + +# Use Debian 13 "Trixie" (latest stable release) +FROM debian:13 + +# Set build argument for fpm version (can be overridden at build time) +ARG FPM_VERSION=1.16.0 + +# Install system dependencies including Python build dependencies +RUN apt-get update && \ + apt-get install -y --no-install-recommends \ + curl \ + git \ + build-essential \ + ruby \ + ruby-dev \ + gcc \ + make \ + zlib1g-dev \ + ca-certificates \ + tcl8.6 \ + tk8.6 \ + tcl8.6-dev \ + tk8.6-dev \ + libx11-6 \ + libxext6 \ + libxrender1 \ + libxcb1 \ + libbz2-dev \ + libreadline-dev \ + libsqlite3-dev \ + libssl-dev \ + libffi-dev \ + wget \ + tar \ + liblzma-dev \ + patch && \ + apt-get clean && \ + rm -rf /var/lib/apt/lists/* + +# Install pyenv +ENV PYENV_ROOT="/root/.pyenv" +ENV PATH="$PYENV_ROOT/bin:$PATH" + +RUN git clone https://github.com/pyenv/pyenv.git /root/.pyenv + +# Install Python 3.12 via pyenv +RUN eval "$(pyenv init -)" && \ + pyenv install 3.12.0 && \ + pyenv global 3.12.0 && \ + pyenv rehash + +# Update PATH to include pyenv shims +ENV PATH="/root/.pyenv/shims:$PATH" + +# Install Poetry +RUN curl -sSL https://install.python-poetry.org | python3 - --yes + +# Add Poetry to PATH +ENV PATH="/root/.local/bin:$PATH" + +# Verify Poetry installation +RUN poetry --version + +# Install fpm +RUN gem install --no-document -v "${FPM_VERSION}" fpm + +# Set working directory +WORKDIR /workspace + +# Set environment variables for build +ENV CI_CD=true +ENV DISTRO_TYPE=debian + +# Default command runs the build script +CMD ["sh", "-c", "poetry install --no-interaction && poetry run python scripts/build_package_linux.py"] diff --git a/scripts/docker/Dockerfile.rhel b/scripts/docker/Dockerfile.rhel index d769dd6..8ae823b 100644 --- a/scripts/docker/Dockerfile.rhel +++ b/scripts/docker/Dockerfile.rhel @@ -5,7 +5,7 @@ # docker build -f scripts/docker/Dockerfile.rhel -t android-file-handler-rhel-builder . # docker run -v $(pwd):/workspace -w /workspace android-file-handler-rhel-builder -FROM fedora:latest +FROM fedora:42 # Set build argument for fpm version (can be overridden at build time) ARG FPM_VERSION=1.16.0