From 0d51a990cc840b6dd9a4d141e13d637ae53fa624 Mon Sep 17 00:00:00 2001 From: Dianjin Wang Date: Tue, 22 Sep 2026 16:27:19 +0800 Subject: [PATCH] Drop the prebuilt gppkg samples and widen the binary check The Incubator releasecheck tool reports binary files in the 2.2.0-rc1 source archive. Looking at each one, only two are avoidable. gpMgmt/demo/gppkg/data/ held a .deb and an .rpm, and they are output of the script sitting beside them: generate_sample_gppkg.sh writes them there in buildNative and reads them back in buildGppkg. Anyone who needs them can run the first step, which is what its README already describes, so they go. The rest stay and are recorded instead: - the sample.gppkg the gppkg behave suite installs, which has to be a real package because the tests exercise package handling - src/bin/pgevent/MSG00001.bin, which comes from PostgreSQL, is referenced by pgmsgevent.rc, and is described by the README next to it. Cloudberry never builds it: src/bin/Makefile only adds pgevent to SUBDIRS when PORTNAME is win32 Widening the check matters as much as the deletion. It looked at class, jar, tar, tgz, zip, exe, dll, so, gz and bz2, so none of the files the tool found would have tripped it, including the two removed here. It now covers deb, rpm, gppkg and bin as well, with the two kept files allowlisted. README.apache.md gains a section giving the reason for each allowlisted file, and records the PAX Python API test data (contrib/pax_storage/src/api/python3/test/test.file*). Those are PAX-format fixtures read by paxpy_test.py, one per set of column types. Their names carry no extension the check can match, so documenting them is all that is possible; they are listed so the set is not invisible. Checked by running the workflow's allowlist logic over the tree: with deb, rpm, gppkg and bin added, every matching file is accounted for, and every allowlist entry still exists. Assisted-by: Claude Code Backpatch-through: REL_2_STABLE --- .github/workflows/apache-rat-audit.yml | 6 ++-- README.apache.md | 28 ++++++++++++++++++ gpMgmt/demo/gppkg/data/sample-0.0-1.amd64.deb | Bin 888 -> 0 bytes .../gppkg/data/sample-0.0.1-noop.x86_64.rpm | Bin 2484 -> 0 bytes 4 files changed, 32 insertions(+), 2 deletions(-) delete mode 100644 gpMgmt/demo/gppkg/data/sample-0.0-1.amd64.deb delete mode 100644 gpMgmt/demo/gppkg/data/sample-0.0.1-noop.x86_64.rpm diff --git a/.github/workflows/apache-rat-audit.yml b/.github/workflows/apache-rat-audit.yml index 53df0a40b40..6cecf9dbabb 100644 --- a/.github/workflows/apache-rat-audit.yml +++ b/.github/workflows/apache-rat-audit.yml @@ -115,7 +115,7 @@ jobs: - name: Check for binary files run: | echo "Checking for binary files..." - echo "Checking extensions: class, jar, tar, tgz, zip, exe, dll, so, gz, bz2" + echo "Checking extensions: class, jar, tar, tgz, zip, exe, dll, so, gz, bz2, deb, rpm, gppkg, bin" echo "----------------------------------------------------------------------" # Binary file allowlist, see README.apache.md @@ -127,10 +127,12 @@ jobs: "src/bin/gpfdist/regress/data/gpfdist2/gz_multi_chunk_2.tbl.gz" "src/bin/gpfdist/regress/data/gpfdist2/lineitem.tbl.bz2" "src/bin/gpfdist/regress/data/gpfdist2/lineitem.tbl.gz" + "gpMgmt/test/behave/mgmt_utils/steps/data/sample.gppkg" + "src/bin/pgevent/MSG00001.bin" ) # Check for specific binary file extensions - binary_extensions="class jar tar tgz zip exe dll so gz bz2" + binary_extensions="class jar tar tgz zip exe dll so gz bz2 deb rpm gppkg bin" echo "BINARY_EXTENSIONS=${binary_extensions}" >> $GITHUB_ENV binary_results="" binaryfiles_found=false diff --git a/README.apache.md b/README.apache.md index e99f2b2328f..adeedace124 100644 --- a/README.apache.md +++ b/README.apache.md @@ -50,3 +50,31 @@ The following compressed files are included in the source tree. These files are - src/bin/gpfdist/regress/data/gpfdist2/gz_multi_chunk_2.tbl.gz - src/bin/gpfdist/regress/data/gpfdist2/lineitem.tbl.bz2 - src/bin/gpfdist/regress/data/gpfdist2/lineitem.tbl.gz + +## Binary Files in Source + +A source release should not carry compiled artifacts, so the licence audit +workflow fails on binary file extensions unless the file is allowlisted. The +following are allowed, with the reason for each. + +- gpMgmt/test/behave/mgmt_utils/steps/data/sample.gppkg + + A small sample package that the `gppkg` behave suite installs and removes. + The tests exercise package handling itself, so the fixture has to be a real + package. + +- src/bin/pgevent/MSG00001.bin + + Inherited from PostgreSQL, where it is also shipped. It is the output of the + Microsoft Message Compiler and is referenced from `pgmsgevent.rc` when + building the Windows event log DLL; `src/bin/pgevent/README` describes how it + is produced. Cloudberry does not build it: `src/bin/Makefile` only puts + `pgevent` in `SUBDIRS` when `PORTNAME` is `win32`. + +The PAX Python API test data under +`contrib/pax_storage/src/api/python3/test/` (`test.file1` through `test.file9`, +plus `test.file3.vm1`, `test.file3.vm2` and `test.file7.toast`) is also binary: +each file is a PAX-format data file covering a particular set of column types, +read by `paxpy_test.py`. These names carry no recognised extension, so the +workflow's extension-based check does not see them; they are recorded here so +the set is documented rather than invisible. diff --git a/gpMgmt/demo/gppkg/data/sample-0.0-1.amd64.deb b/gpMgmt/demo/gppkg/data/sample-0.0-1.amd64.deb deleted file mode 100644 index 729515c6593c614928a14686eceff4e78f4c41df..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 888 zcmY$iNi0gvu;WTeP0CEn(@o0EODw8XP*5;5H8V0YGO#o-Qcy4e@?oT*fq|KciGl(U zK|unSk)8opa(-S(QGSkINn(*+MHONF#ugTE{eR7?BBB@=Se{+m;>L2|FjGT-BBK}s z1O$EZD1V^-pV2y&L7aP!OfBQo1F~Lrm7<5vs4b3kC=_wHs+##_>QRNAcasXjGJm)x z?JZyuUbNol|H91*2e-Hx&Mz*0V)HNit-7`SfolwEufMVIUVmz78yWI3K5NEeUOS%M z^7~7VJdilPs?TkInc>Rh(rSP9CmRo3;I8tRy2J8upQp&ZNnA>4>pdrPc?HXEx6-xC zH4EH)x%nrDFi%f~sp+$+(Jyq0?yg@t*|Ff{i2~)XvM2uftiAJNceiUu)ty<_)@`p^ zcQb0EU{>#{Bh!BOy6=@Z*^4TJFQ6>Zp#g~SWM!2B*ib_z`*cRZ^QdJ!gp^mFy04-F9XAw zjS{yv9!dYr1PW%B$f%UWl0@n`6g5<9Q` z;Ou~BC3hXK##stli3N3Bmg#=FomICihwU*}=7MtN)2>ehnG62Q#=l+nS+mD>nyk&S zC*rBenoBYp3#V?mpQ`xdy`dl18H*#{6TD-O^3*U~R8wLX5D+|QB(%%1MPKoF3Xk4WIJ*eT`rL7E09GFB@qI7QD zJ?Fe;nFFJlx~R#s{>3x8cXse!GrT#)^T6LH@8@xNO-xo?f8rejW1HZI4A%FD3U>DO wJ8_@j+1t@G`|i@be8ub?eF6uj^nil2U7{tQf4;sx17jaJyys<|l0gn{01)_FQ~&?~ diff --git a/gpMgmt/demo/gppkg/data/sample-0.0.1-noop.x86_64.rpm b/gpMgmt/demo/gppkg/data/sample-0.0.1-noop.x86_64.rpm deleted file mode 100644 index ab635f140a30f17fc2a73bc10d7fcd739346e7ba..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 2484 zcmds3Yitx%6uz@vOL+-W4bY%jz$gtnyF0V9k1?%nECNL%6{rGI>&)z(?Zn-kVP>{0 z6%#QUY9tbQ7!&=2Vj`kZ6GQmH(?BG~A120Eh!IGQRC(whBhPxy&RJdb2m05$Irp3I zoO92dd+uZQ+@A9%8W=Re(~3@ki-}kwCW$56c2N7@n!s-Q`+%3;J0p+|Z7V?T1sMmj z0Awn>crsuk2sZF-I0G04i4s2xi2ex>@Nc*Pi1tnp!N?e9R+iO7lBW$dora!EQZ|uH zW)nHhFikC?W-?p`UuaFQ@Ac0fyZH3nHsQd?xY_5AWEl$$gQ1$!*x1+y@C@%@tS)aD z8%CcF5Xd830Ysl1ND~OQTHZL15b;q!*8qX2OSjaaMpAaD1 zPJALD)?*j(NdXt$CXVY2@r8GZV;#U>*iRg5iu`lpSQp4a7y*R&gl`M59 zAsh#Jg=Yl%P=f3;$=*r4h4`Dq=K(_e&>=vKzbMd$j+1>c@o$KC1LFJ65MM$Z*Ad6B z4D_L205P9cWWPduO<-@pd13y2fxY2Q;*S%@_n=(|g!~#@K#ZRYco^3KIVXNIag+Eh z#0$imiPzRO3LN8?32}cR9|VN?g&zdO`0Gf&g0Mn}d4PZOHsTmp=wiYB!K(KMtKJ_z zhZ{xndBk;!te!;jyu@A2x9k#(Wqq^yw`P)(o|7asmykP4SS6e8Pb+~_UB7Wx@T;jXZoTlNo-h(YPXU zC9SBsnp6x;QB$fa>6vUw*0ZS;`yT|T)utX@+xFSN=>GAAhu zTVJrXs7#eQx-+D|)_bmmrepXs%Xl_dG|`%cjY}Vh!6D5t&kbn4SUtI7zJ#~V z4H{e<{`wpEkQwV={VtDShBmPm`q+%g z--UJgVtL{-ZycENaN|=)ADB7q%N+;jj|@j&9`|+Xqtn9n(=DS%o3zH|<8wcLyJYjJ zNa$E`(x+b}K1}T?va3z6uHI2N*l~E^lidP4bx-g7J2uWL4=2{>mws+plRdQd?i1VQ zT>5y+S618pj^sP9P4|zVi*^j|9(i`^mgo~dG#)&BZS;}m&bvN?tQZ@d)4HK_W#5ta zZ-1+A{qw0;dd4?*Z@3(}kH5He$%W<}G7}C6!|<=^;?6~bdq=;YRsHf!She~Oj*;SC