Three merges landed within 45 seconds on 2026-09-12 and each started its own
run of both package workflows. Every run publishes, so a burst of merges puts
several uploads into the repo for what is effectively one state of the tree.
Add a concurrency group per workflow and branch with cancel-in-progress, so a
newer push supersedes a build still in flight rather than racing it into the
incoming directory. This also stops the matrix rebuilding fourteen containers
for a commit that is already stale.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UkQwahn9pi1y4wJe9BTxjM
The snapshot component is date plus the number of commits since version.txt
last changed, so every build of the same tip on the same day produces the same
version string. The repo operator reports 96% of version+dist pairs published
more than once, and 1.39.34~20260912.22-bookworm1 uploaded six times in about
half an hour, each upload overwriting the last with different bytes.
Nothing on the repo server can close that. Reindexing shrinks the window but a
client that read Packages before a republish and fetched the .deb after it still
gets a hash mismatch, because the version no longer identifies the content.
Append GITHUB_RUN_ID and GITHUB_RUN_ATTEMPT, which are unique per build and
never reused. Outside Actions the string is unchanged, so a local build still
produces the version it always did.
Checked that the longer string still sorts after the versions already published
and before the next version.txt bump, with dpkg --compare-versions and
rpm.vercmp.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UkQwahn9pi1y4wJe9BTxjM
Nothing in CI compiles for anything but Linux, so Linux-only APIs reach
master unnoticed. dep/RtspServer calling pipe2() sat in master until a
native build was attempted by hand.
Builds on macos-latest with Homebrew deps and runs the Catch2 suite.
Notes on the choices:
- macos-latest, so the job follows whatever macOS GitHub ships (arm64,
macOS 26 at time of writing). The bare label is a standard runner and
free on public repos; -large and -xlarge are billed even here.
- mysql-client is keg-only, so the bare find_library in CMakeLists.txt
misses it and the build dies on "'mysql/mysql.h' file not found".
Hence the explicit -I alongside CMAKE_PREFIX_PATH.
- gsoap is installed although optional, so ONVIF is covered on macOS.
Without it the suite runs 138 cases instead of 144.
- Runs the test binary rather than ctest, matching ci-cpp-tests.yml:
catch_discover_tests does not map Catch2 tags onto ctest labels, so
ctest cannot skip [notCI], and zm_font.cpp loads fixtures by relative
path.
- push filter is '**' rather than '*', which does not match branch names
containing a slash.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B5KL9Xbi7K5aGsauLtd8tG
Nothing in CI built tests/ at all. The packaging workflows and the -Werror job
all configure with BUILD_TEST_SUITE off, which is why the two Catch2 v2 leftovers
fixed in the previous commit sat there breaking the build unnoticed.
Pinned to ubuntu-24.04 rather than ubuntu-latest because the suite needs Catch2
v3 and noble is what packages it.
Runs the binary rather than ctest. catch_discover_tests does not carry Catch2
tags through as ctest labels, so ctest cannot skip the [notCI] cases that want a
reachable database or a listening socket, and zm_font.cpp loads its fixtures by
relative path so the working directory has to be the one the build copied
tests/data into.
Verified with a fresh out-of-source configure and build using the same commands
as the workflow: 144 test cases, 12480 assertions, exit 0.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
tests/js holds eight files and 154 assertions covering auth-helpers,
EventStream, MonitorStream, table-helpers, the encoder templates and the zone
object size tool. No workflow ran any of them, so they only ever executed if
someone thought to run them by hand, and ci-eslint only checks that the source
parses and conforms to style.
The tests need nothing installed: they use node builtins (assert, fs, path,
vm) and files from web/js, so there is no npm install step and no submodule
to fetch.
The loop keeps going after a failure and fails at the end, so one CI run
reports every broken test rather than stopping at the first.
Verified by extracting the run script from the YAML and executing it: exit 0
with all eight files run, and after deliberately failing an assertion in the
first file, exit 1 with all eight still run.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UvTCzCbvGt8xKQRNCSA7o8
The amd64 and aarch64 deb workflows build the same distro matrix, so both
produced zoneminder-doc_<version>_all.deb and uploaded it to the same
mini-dinstall incoming directory at the same time, racing each other and
offering mini-dinstall the same file twice.
Add a binary-arch build type to do_debian_package.sh that runs debuild -B,
and use it from the aarch64 workflow. The arm .changes then references only
arm64 packages and the arch-independent debs come from amd64 alone.
mini-dinstall moves files out of incoming/ while a job is uploading, so the
rsync receiver can generate block checksums for a basis file that disappears
before the transfer completes, failing with "got a block match with no basis
file". .deb payloads are already compressed, so delta transfer buys nothing
here anyway.
Every CI runner is 64bit, so nothing in CI exercised the 32bit SharedData
layout that zmc/zma/zms, ZoneMinder::Memory and web/includes/Monitor.php
all have to agree on. The i386 alignment divergence that broke the 32bit
build was only caught downstream.
utils/check-shareddata-abi.py lifts the struct body and its static_asserts
out of zm_monitor.h, compiles them standalone at -m32 and -m64, and
requires the size and every member offset to match. Compiling only the
struct avoids needing a 32bit copy of the ffmpeg, mysql and curl headers;
gcc-multilib alone is enough and the check takes about a second, so it
runs before the build rather than after it.
The expected size is never duplicated in the script. It comes from the
assertions in the header, so there is one source of truth and the script
cannot drift from it. Removing the assertions is itself reported as a
failure, since deleting the guard is the tempting way to silence a 32bit
build error.
Verified by reverting the epadding members, which reproduces the original
downstream failure (880 == 888) and additionally names capture_fps,
startup_time and control_state, and by deleting the assertions, which is
reported as a missing guard.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
GCC emits a whole class of warnings only from its optimizer passes, so
they cannot appear in the -O0 Debug trees used for local development:
-Wclobbered, -Wmaybe-uninitialized, -Wstringop-truncation,
-Wstringop-overflow, -Warray-bounds, -Wdangling-pointer, -Wuse-after-free.
Nothing in CI closed that gap. The deb/rpm workflows build Release and
did print these warnings, but never set ENABLE_WERROR, so they scrolled
past as log noise. The only -Werror build is .cirrus.yml, which is
FreeBSD/clang, and clang does not implement -Wclobbered at all. The three
conditions therefore intersected only in the downstream Docker build,
which is where such warnings first broke a build.
Third-party diagnostics are demoted to warnings so they cannot fail the
build: system mosquittopp.h carries a #warning, and gsoap's wsseapi.c
casts between function and object pointers. Warnings in ZoneMinder's own
sources stay hard errors.
Pinned to ubuntu-24.04 rather than ubuntu-latest because -Wclobbered is
sensitive to compiler version and inlining, so a GCC bump should be a
deliberate change rather than a surprise CI failure.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The four package workflows upload every built .deb/.rpm as a run artifact
and then rsync the same files to ZMREPO in the next step. The only consumer
of the artifacts is the `release` job, which is gated on
startsWith(github.ref, 'refs/tags/'). On branch pushes to master and
release-1.38 nothing ever reads them, so each push was parking ~1.3 GB of
artifacts against the org Actions storage quota for their full one-day
retention. Three pushes in a day held ~3.9 GB at once.
Gate each upload step on the same tag condition the `release` job uses, so
the artifacts exist exactly when something consumes them. Branch pushes
still publish to ZMREPO unchanged; tag builds are unaffected.
This also skips the artifact upload itself on branch pushes, which saves
transfer time on the self-hosted aarch64 runners.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0179XFS73S5t4PM4L8zomZHX
Fedora 44 images come with Fedora's stripped ffmpeg libraries installed
(libavutil-free, libswresample-free). RPMFusion's ffmpeg-libs, which
satisfies the spec's BuildRequires on ffmpeg-devel, declares Conflicts
against those, so builddep fails to depsolve:
installed package libswresample-free-8.1.2-1.fc44.x86_64 conflicts
with libswresample-free provided by ffmpeg-libs-8.1.2-2.fc44.x86_64
from rpmfusion-free-updates
Pass --allowerasing so dnf swaps the -free libraries for the RPMFusion
ffmpeg-libs, matching what the systemd install in the build tools step
already does.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NZhAPb2indRrLWSEJ87kf8
Add fedora:44 to the build matrix in build-rpm-packages.yml and
build-rpm-packages-aarch64.yml, and to the DISTROS list in
utils/zmrepo_mkdirs.sh so the repo tree gets an rpm/master/fedora/44
directory for the deploy rsync.
Fall back to rpmfusion-free-release-rawhide.noarch.rpm in the x86_64
workflow when the versioned release RPM is missing, matching what the
aarch64 workflow already does. Fedora 44 is rawhide, so
rpmfusion-free-release-44.noarch.rpm does not exist yet.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NZhAPb2indRrLWSEJ87kf8
Cyrillic/Greek characters that look like ASCII letters keep landing in the
tree from pasted contributions (discussions #4993, #4678, PR #4678), breaking
lookups and getting corrupted by reverse proxies. utils/check-homoglyphs.py
scans the git-tracked source for characters in the Cyrillic (U+0400-U+04FF)
and Greek (U+0370-U+03FF) blocks and exits non-zero on any hit, excluding
translations (web/lang/) and vendored/minified assets where they are
legitimate. A CI Homoglyphs workflow runs it on push and pull request, and it
can be run locally with python3 utils/check-homoglyphs.py.
refs https://github.com/ZoneMinder/zoneminder/discussions/4993
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KQipwf632JGgNH4W7p8cqs
The build-rpm-packages workflows deploy with easingthemes/ssh-deploy using
rsync args -rltgoDzvO, which does not create missing parent directories on
the remote. When the zmrepo directory tree was deleted the deploy step
failed.
--mkpath is not a viable fix: it is parsed by the local rsync in the build
container, and Rocky 8 ships rsync 3.1.3 which predates the flag (3.2.3+).
Add a pre-deploy step that creates rpm/master/<family>/<releasever>/<arch>/
over ssh with mkdir -p, which has no rsync version dependency. Also add
utils/zmrepo_mkdirs.sh to recreate the full tree manually.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
CodeQL's open alerts are dominated by findings inside bundled third-party
libraries (jQuery UI, Bootstrap 4, bootstrap-table, the jQuery UI
timepicker addon, hls.js). These flag coding patterns internal to those
libraries -- js/unsafe-jquery-plugin, js/insecure-randomness, etc. -- that
are not ZoneMinder bugs and cannot be fixed without forking the
dependencies. They drown out findings in ZoneMinder-authored code.
Add the vendored library directories/files to paths-ignore in the CodeQL
config. ZoneMinder-authored files in these trees (skin.js,
MonitorStream.js, views/js/*.js, ...) are not listed and remain analysed.
moment.js is intentionally left out: it is scheduled for removal once its
remaining call sites migrate to luxon, so its alert will be resolved by
deletion rather than suppression.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
GitHub's auto-generated 'Source code' release assets are plain git
archive output without submodules, so cmake fails immediately on the
submodule check and the release cannot be built standalone.
On every published release (or manual dispatch with a tag, to backfill
existing releases) build zoneminder-<tag>.tar.gz from a recursive
checkout and attach it plus a sha256 to the release. The tarball is
reproducible (commit mtime, sorted entries, no owner, no gzip
timestamp) and is sanity-checked for the same file CMakeLists.txt
requires before upload.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds paths-ignore for db/, docs/, distros/, misc/, onvif/, scripts/
and *.md/*.sql/*.in files. CodeQL analyses cpp and javascript only,
so changes confined to these paths produce no new findings and don't
need to spend Actions minutes or generate ~610 MB of cache.
Verified the ignored directories contain no .c/.cpp/.h/.js files.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Runs daily at 03:00 UTC and via workflow_dispatch. Groups caches by
key prefix (stripping trailing run/sha suffixes) and keeps the N
newest per prefix, deleting the rest. Defaults to keeping 2.
Without this, CodeQL builds left ~10 GB of per-commit caches behind,
exhausting the org Actions storage quota.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Two changes that together stop the .orig.tar.gz from landing in
mini-dinstall's incoming dir and causing cross-distro filename
collisions:
- do_debian_package.sh: quote DEBUILD assignment so the -b flag is
actually passed to debuild. Without quotes, bash parsed it as
"run -b with DEBUILD=debuild as one-shot env", dropping the binary
flag and falling back to a full source build that included the orig
tarball in .changes.
- build-deb-packages{,-aarch64}.yml: drop *.dsc, *.tar.xz, *.tar.gz
from the artifact collection mv. Only .deb, .buildinfo, and .changes
are needed for binary uploads.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
ESLint 9 ignores the --ext flag, so the old --ext .js.php,.js had no
effect. The flat config's **/*.*php glob matched all .php files, not
just .js.php. Add explicit files pattern to the main config block and
narrow the PHP override from **/*.*php to **/*.js.php. Remove the
now-ignored --ext flag from CI and docs.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@eslint/js@10.0.1 requires eslint@^10.0.0 as a peer dependency,
which conflicts with the pinned eslint@9. Pinning @eslint/js to <10
keeps it on the 9.x line.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Complete the migration from .eslintrc.js to eslint.config.js flat
config format for ESLint 9 compatibility. Add valid-jsdoc: off
(removed in ESLint 9 but enabled by eslint-config-google) and the
missing operator-linebreak: off override. Update the HLS ignore path
to match current version. Update CI workflow to install ESLint 9 and
its flat config dependencies.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace hardcoded release-1.38 references with GITHUB_REF_NAME so the
workflows use the branch they are running on for the -b parameter, curl
source URL, and rsync deploy targets. Non-tag pushes deploy to
proposed-<version>, tag pushes deploy to release-<version>.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
When triggered by a tag push, pass the release tag to
do_debian_package.sh via -r= flag. Branch pushes continue
to use -s=CURRENT.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Change curl URL from refs/heads/master to refs/heads/release-1.38
in both x86 and aarch64 workflows
- Uncomment safe.directory config in x86 workflow to fix dubious
ownership error
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>