Every CI runner is 64bit, so nothing in CI exercised the 32bit SharedData
layout that zmc/zma/zms, ZoneMinder::Memory and web/includes/Monitor.php
all have to agree on. The i386 alignment divergence that broke the 32bit
build was only caught downstream.
utils/check-shareddata-abi.py lifts the struct body and its static_asserts
out of zm_monitor.h, compiles them standalone at -m32 and -m64, and
requires the size and every member offset to match. Compiling only the
struct avoids needing a 32bit copy of the ffmpeg, mysql and curl headers;
gcc-multilib alone is enough and the check takes about a second, so it
runs before the build rather than after it.
The expected size is never duplicated in the script. It comes from the
assertions in the header, so there is one source of truth and the script
cannot drift from it. Removing the assertions is itself reported as a
failure, since deleting the guard is the tempting way to silence a 32bit
build error.
Verified by reverting the epadding members, which reproduces the original
downstream failure (880 == 888) and additionally names capture_fps,
startup_time and control_state, and by deleting the assertions, which is
reported as a missing guard.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
GCC emits a whole class of warnings only from its optimizer passes, so
they cannot appear in the -O0 Debug trees used for local development:
-Wclobbered, -Wmaybe-uninitialized, -Wstringop-truncation,
-Wstringop-overflow, -Warray-bounds, -Wdangling-pointer, -Wuse-after-free.
Nothing in CI closed that gap. The deb/rpm workflows build Release and
did print these warnings, but never set ENABLE_WERROR, so they scrolled
past as log noise. The only -Werror build is .cirrus.yml, which is
FreeBSD/clang, and clang does not implement -Wclobbered at all. The three
conditions therefore intersected only in the downstream Docker build,
which is where such warnings first broke a build.
Third-party diagnostics are demoted to warnings so they cannot fail the
build: system mosquittopp.h carries a #warning, and gsoap's wsseapi.c
casts between function and object pointers. Warnings in ZoneMinder's own
sources stay hard errors.
Pinned to ubuntu-24.04 rather than ubuntu-latest because -Wclobbered is
sensitive to compiler version and inlining, so a GCC bump should be a
deliberate change rather than a surprise CI failure.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
The four package workflows upload every built .deb/.rpm as a run artifact
and then rsync the same files to ZMREPO in the next step. The only consumer
of the artifacts is the `release` job, which is gated on
startsWith(github.ref, 'refs/tags/'). On branch pushes to master and
release-1.38 nothing ever reads them, so each push was parking ~1.3 GB of
artifacts against the org Actions storage quota for their full one-day
retention. Three pushes in a day held ~3.9 GB at once.
Gate each upload step on the same tag condition the `release` job uses, so
the artifacts exist exactly when something consumes them. Branch pushes
still publish to ZMREPO unchanged; tag builds are unaffected.
This also skips the artifact upload itself on branch pushes, which saves
transfer time on the self-hosted aarch64 runners.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0179XFS73S5t4PM4L8zomZHX
Fedora 44 images come with Fedora's stripped ffmpeg libraries installed
(libavutil-free, libswresample-free). RPMFusion's ffmpeg-libs, which
satisfies the spec's BuildRequires on ffmpeg-devel, declares Conflicts
against those, so builddep fails to depsolve:
installed package libswresample-free-8.1.2-1.fc44.x86_64 conflicts
with libswresample-free provided by ffmpeg-libs-8.1.2-2.fc44.x86_64
from rpmfusion-free-updates
Pass --allowerasing so dnf swaps the -free libraries for the RPMFusion
ffmpeg-libs, matching what the systemd install in the build tools step
already does.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NZhAPb2indRrLWSEJ87kf8
Add fedora:44 to the build matrix in build-rpm-packages.yml and
build-rpm-packages-aarch64.yml, and to the DISTROS list in
utils/zmrepo_mkdirs.sh so the repo tree gets an rpm/master/fedora/44
directory for the deploy rsync.
Fall back to rpmfusion-free-release-rawhide.noarch.rpm in the x86_64
workflow when the versioned release RPM is missing, matching what the
aarch64 workflow already does. Fedora 44 is rawhide, so
rpmfusion-free-release-44.noarch.rpm does not exist yet.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NZhAPb2indRrLWSEJ87kf8
Cyrillic/Greek characters that look like ASCII letters keep landing in the
tree from pasted contributions (discussions #4993, #4678, PR #4678), breaking
lookups and getting corrupted by reverse proxies. utils/check-homoglyphs.py
scans the git-tracked source for characters in the Cyrillic (U+0400-U+04FF)
and Greek (U+0370-U+03FF) blocks and exits non-zero on any hit, excluding
translations (web/lang/) and vendored/minified assets where they are
legitimate. A CI Homoglyphs workflow runs it on push and pull request, and it
can be run locally with python3 utils/check-homoglyphs.py.
refs https://github.com/ZoneMinder/zoneminder/discussions/4993
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KQipwf632JGgNH4W7p8cqs
The build-rpm-packages workflows deploy with easingthemes/ssh-deploy using
rsync args -rltgoDzvO, which does not create missing parent directories on
the remote. When the zmrepo directory tree was deleted the deploy step
failed.
--mkpath is not a viable fix: it is parsed by the local rsync in the build
container, and Rocky 8 ships rsync 3.1.3 which predates the flag (3.2.3+).
Add a pre-deploy step that creates rpm/master/<family>/<releasever>/<arch>/
over ssh with mkdir -p, which has no rsync version dependency. Also add
utils/zmrepo_mkdirs.sh to recreate the full tree manually.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
GitHub's auto-generated 'Source code' release assets are plain git
archive output without submodules, so cmake fails immediately on the
submodule check and the release cannot be built standalone.
On every published release (or manual dispatch with a tag, to backfill
existing releases) build zoneminder-<tag>.tar.gz from a recursive
checkout and attach it plus a sha256 to the release. The tarball is
reproducible (commit mtime, sorted entries, no owner, no gzip
timestamp) and is sanity-checked for the same file CMakeLists.txt
requires before upload.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Adds paths-ignore for db/, docs/, distros/, misc/, onvif/, scripts/
and *.md/*.sql/*.in files. CodeQL analyses cpp and javascript only,
so changes confined to these paths produce no new findings and don't
need to spend Actions minutes or generate ~610 MB of cache.
Verified the ignored directories contain no .c/.cpp/.h/.js files.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Runs daily at 03:00 UTC and via workflow_dispatch. Groups caches by
key prefix (stripping trailing run/sha suffixes) and keeps the N
newest per prefix, deleting the rest. Defaults to keeping 2.
Without this, CodeQL builds left ~10 GB of per-commit caches behind,
exhausting the org Actions storage quota.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Two changes that together stop the .orig.tar.gz from landing in
mini-dinstall's incoming dir and causing cross-distro filename
collisions:
- do_debian_package.sh: quote DEBUILD assignment so the -b flag is
actually passed to debuild. Without quotes, bash parsed it as
"run -b with DEBUILD=debuild as one-shot env", dropping the binary
flag and falling back to a full source build that included the orig
tarball in .changes.
- build-deb-packages{,-aarch64}.yml: drop *.dsc, *.tar.xz, *.tar.gz
from the artifact collection mv. Only .deb, .buildinfo, and .changes
are needed for binary uploads.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
ESLint 9 ignores the --ext flag, so the old --ext .js.php,.js had no
effect. The flat config's **/*.*php glob matched all .php files, not
just .js.php. Add explicit files pattern to the main config block and
narrow the PHP override from **/*.*php to **/*.js.php. Remove the
now-ignored --ext flag from CI and docs.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@eslint/js@10.0.1 requires eslint@^10.0.0 as a peer dependency,
which conflicts with the pinned eslint@9. Pinning @eslint/js to <10
keeps it on the 9.x line.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Complete the migration from .eslintrc.js to eslint.config.js flat
config format for ESLint 9 compatibility. Add valid-jsdoc: off
(removed in ESLint 9 but enabled by eslint-config-google) and the
missing operator-linebreak: off override. Update the HLS ignore path
to match current version. Update CI workflow to install ESLint 9 and
its flat config dependencies.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace hardcoded release-1.38 references with GITHUB_REF_NAME so the
workflows use the branch they are running on for the -b parameter, curl
source URL, and rsync deploy targets. Non-tag pushes deploy to
proposed-<version>, tag pushes deploy to release-<version>.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
When triggered by a tag push, pass the release tag to
do_debian_package.sh via -r= flag. Branch pushes continue
to use -s=CURRENT.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
- Change curl URL from refs/heads/master to refs/heads/release-1.38
in both x86 and aarch64 workflows
- Uncomment safe.directory config in x86 workflow to fix dubious
ownership error
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Trigger on release-1.38 instead of master, rsync builds to proposed
directory, and rsync tagged releases to release-1.38 directory.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Trigger on release-1.38 instead of master, rsync builds to proposed
directory, and rsync tagged releases to release-1.38 directory.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
The monitorStatus HTML was conditionally omitted based on
ZM_WEB_COMPACT_MONTAGE, leaving the status position dropdown
with no elements to operate on. Always render the HTML and
use the dropdown's hidden option to handle compact montage
instead.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
On Fedora 43, net-tools pulls in systemd which conflicts with
systemd-standalone-tmpfiles in container build environments.
Pre-define ZM_PATH_ARP, ZM_PATH_ARP_SCAN, ZM_PATH_IP, and
ZM_PATH_IFCONFIG in the cmake call instead of relying on
find_program() at build time.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
On Fedora 43, net-tools pulls in systemd which conflicts with
systemd-standalone-tmpfiles in container build environments.
Pre-define ZM_PATH_ARP, ZM_PATH_ARP_SCAN, ZM_PATH_IP, and
ZM_PATH_IFCONFIG in the cmake call instead of relying on
find_program() at build time.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Fedora 43 container images ship systemd-standalone-tmpfiles which
conflicts with the full systemd package. Packages like mosquitto
and net-tools depend on systemd, causing dnf builddep to fail.
Install systemd with --allowerasing before builddep to resolve.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>