Skip to content

build: pin every source-built tool and the Rust toolchain - #35

Merged
nucliweb merged 1 commit into
mainfrom
build/pin-versions
Oct 2, 2026
Merged

nucliweb merged 1 commit into
mainfrom
build/pin-versions

Conversation

@nucliweb

@nucliweb nucliweb commented Oct 2, 2026 •

Copy link
Copy Markdown
Owner

Summary

ADR 0002 says tool versions are pinned, and the regression gate relies on that, but four inputs floated:

Input Before After
jpegli main 031a0077f579
flip main b475eb4bf394 (v1.7)
butteraugli master 71b18b636b9c
Rust toolchain latest stable 1.99.0
dssim / oxipng latest 3.5.1 / 10.2.1, --locked
  • The three repos publish no release tags, so they are pinned to the commits the current image was built from. git clone --branch cannot take a commit, hence git init + fetch + checkout.
  • --locked builds each crate with its own Cargo.lock, pinning transitive dependencies too.
  • ADR 0002 now states what is pinned, and that apt packages still follow Debian point releases (security fixes), with the size gate catching an output change.

Test plan

  • docker build succeeds; the log shows rustc 1.99.0, dssim 3.5.1, oxipng 10.2.1
  • smoke-test.sh in the image: 42 ok, 0 failed (butteraugli builds and runs)
  • Full test suite in the image: 46 pass, 0 skipped
  • Demo comparison passes the regression gate locally; jpegli +0.00% on all images
  • Regression gate on CI (amd64), run 37052217267: no size regressions

jpegli, flip and butteraugli tracked moving branches, and the Rust tools installed whatever was newest at build time, so two builds could differ despite ADR 0002 stating that versions are pinned. Pin those three to the commits the current image uses (they publish no release tags), and fix the Rust toolchain, dssim and oxipng versions with --locked. Document in ADR 0002 that apt packages still follow Debian point releases.
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codec comparison ✅ no size regression

📥 Download the codec report (unzip and open report.html locally).

Size check
Size regression check (tolerance 2.0%)

  ok         kodim04.png  JPEG XL  base 120534 → 120534  (+0.00%)
  ok         kodim04.png  jpegli  base 130656 → 130656  (+0.00%)
  improved   kodim04.png  HEIC  base 141774 → 141631  (-0.10%)
  ok         kodim04.png  AVIF  base 150014 → 150019  (+0.00%)
  ok         kodim04.png  WebP  base 173748 → 173748  (+0.00%)
  ok         kodim04.png  mozjpeg  base 201372 → 201372  (+0.00%)
  ok         kodim19.png  JPEG XL  base 136558 → 136558  (+0.00%)
  ok         kodim19.png  jpegli  base 147032 → 147032  (+0.00%)
  improved   kodim19.png  AVIF  base 148631 → 148498  (-0.09%)
  ok         kodim19.png  HEIC  base 155171 → 155322  (+0.10%)
  ok         kodim19.png  WebP  base 173918 → 173918  (+0.00%)
  ok         kodim19.png  mozjpeg  base 213006 → 213006  (+0.00%)
  ok         kodim23.png  JPEG XL  base 74113 → 74113  (+0.00%)
  ok         kodim23.png  jpegli  base 97039 → 97039  (+0.00%)
  ok         kodim23.png  AVIF  base 111100 → 111556  (+0.41%)
  ok         kodim23.png  mozjpeg  base 130349 → 130349  (+0.00%)
  ok         kodim23.png  WebP  base 140374 → 140374  (+0.00%)
  ok         kodim23.png  HEIC  base 157392 → 157442  (+0.03%)

OK: no size regressions.

@nucliweb
nucliweb merged commit 22dd0f1 into main Oct 2, 2026
2 checks passed
@nucliweb
nucliweb deleted the build/pin-versions branch October 2, 2026 19:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant