Files
fips/packaging/debian
Johnathan Corgan 9a1797d3ed Build CI's release binaries once and reuse the package builder image
The dns-resolver suite's end-to-end scenarios compiled fips and
fips-gateway themselves, in a Debian 12 image with whatever Rust was
current. On GitHub that was a second release build on every run, with no
cache, and it was neither the toolchain nor the build that ships. And
every GitHub package build assembled its builder image from scratch on a
fresh runner: apt, rustup and a source compile of cargo-deb, on both
legs of the release workflow and in CI's package job.

The suite now takes --deb PATH and unpacks the two binaries from the
package with dpkg-deb. The package is built in the pinned floor
container, so its binaries start on all five e2e distributions. Without
--deb the suite builds the package through build-deb-container.sh, the
same fallback the install suite uses, so the inline Debian 12 builder is
gone rather than kept as a second path. A missing --deb file is refused
before any scenario runs, and a missing dpkg-deb is a named error.

In the workflow the dns-resolver leg moves to a job of its own that
downloads the package the install legs use, keeping its displayed check
name. In local CI a shared helper builds the package once for both the
dns-resolver and deb-install suites.

build-deb-container.sh gains --print-image-tag, which prints the image
tag without needing docker, and --image-archive PATH: when the image is
absent and the archive exists it is loaded from there, and when the run
builds the image it is saved there, through a temporary file renamed
into place. An archive that fails to load, or does not hold the expected
tag, is a warning and a rebuild rather than a failed build, since the
archive only saves time.

Both workflows restore the archive from the Actions cache under a key
made from the image tag, so any change that rebuilds the image locally
also misses the cache. Only pushes to maint, master and next save an
entry, so pull requests and topic branches read the default branch's
entry instead of each storing a copy that nothing else can read. A
restored image is not refreshed from apt or the base image until one of
the tag's inputs changes, as was already the case locally.
2026-09-19 11:38:44 +00:00
..