Repository navigation
ci(release): build Linux binaries for glibc 2.35 and check the floor - #2193
Merged
Merged
Conversation
…k floor The Linux release binaries link dynamically against the glibc of the image that builds them. release.yml built on ubuntu-latest (x86_64) and ubuntu-24.04-arm, so the archives needed glibc 2.38 and 2.39 and died in the dynamic loader on Ubuntu 22.04, and the x86_64 floor would rise unannounced whenever GitHub moved the ubuntu-latest label. Build the Linux legs on ubuntu-22.04 and ubuntu-22.04-arm, and add a step that runs scripts/check_glibc_floor.py against omni-dev and omni-dev-mcp. It reads the version-needs table (readelf -V) and fails the leg when the highest non-weak GLIBC_ requirement is above GLIBC_FLOOR (2.35, set once in release.yml). Weak requirements, which the loader treats as non-fatal, are reported but do not fail. State the floor in the README installation section and in a new RELEASE.md section, and add a changelog entry. Closes #2178
Address review of the glibc floor check: - A binary with no parsed GLIBC_ requirement now fails instead of reading as within the floor, so output the parser does not recognise cannot ship an unverified archive. - A missing readelf or unreadable binary exits 2 with an annotation, as the docstring says, instead of exit 1, which means above the floor. - The version-needs table ends at a blank or unindented line rather than at any capitalised "section" line. - A test ties the floor stated in README.md and docs/RELEASE.md to GLIBC_FLOOR in release.yml, and one runs the real readelf on an ELF where available; the fixture comment now says what is verbatim.
CoverageTotal: 97.95% ⚪ 0 pp vs Comparing No per-file coverage changes vs 🔇 269 ignored region(s), 0 tolerated region(s)
Patch coverageNo new executable lines added by this diff. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
The Linux release binaries link dynamically against the glibc of the runner image that builds them.
release.ymlbuilt onubuntu-latest(x86_64) andubuntu-24.04-arm, soomni-dev-linux.tar.gzneeded glibc 2.38 andomni-dev-linux-arm64.tar.gz2.39, and they die in the loader on Ubuntu 22.04. The x86_64 floor would also rise unannounced whenever GitHub moves theubuntu-latestlabel.This builds the Linux legs on
ubuntu-22.04/ubuntu-22.04-arm(glibc 2.35) and adds a build step that fails if a binary needs more than a stated floor. This is options 1 and 3 from the issue; the plan is in the issue comment.Type of Change
Related Issue
Closes #2178
Changes Made
.github/workflows/release.yml: Linux legs onubuntu-22.04/ubuntu-22.04-arm;GLIBC_FLOOR: '2.35'set once inenv; a "Check the glibc floor" step on the Linux legs runs the script onomni-devandomni-dev-mcpbefore archiving.scripts/check_glibc_floor.py: parses the.gnu.version_rtable fromreadelf -V, fails when the highest non-weakGLIBC_x.yis above the floor; weak requirements (the loader's non-fatal case) are reported only. Fails closed when no requirement is parsed. Exit 0/1/2.scripts/test_check_glibc_floor.py: parser, floor logic, exit codes, a real-readelftest (skipped where unavailable) and a guard that the floor stated in the README anddocs/RELEASE.mdmatchesGLIBC_FLOOR.README.md,docs/RELEASE.md(new "Linux glibc floor" section),CHANGELOG.md.Testing
python3 -m unittest discover -s scripts -p 'test_*.py': 90 tests OK (1 skipped locally: needsreadelf).ssh terminus-vanilla): the 16 glibc-floor tests pass with none skipped, and the script run on real binaries givesokat floor 2.35, a failure with exit 1 at floor 2.30, and exit 2 for a missing binary.actionlint .github/workflows/release.yml: only pre-existing shellcheck notes in untouched steps.python3 scripts/check_changelog.py --base origin/mainok;omni-dev git commit message lint origin/main..HEADclean.Not verified
release.ymlruns only on av*tag, so that the crate builds onubuntu-22.04/ubuntu-22.04-armand that the binaries meet 2.35 is first shown by the next release. I expect no problem (gcc 11 builds the C dependencies; the binaries were built on 24.04 before) but have no evidence. If a leg fails, the failure is the same as any release-workflow defect (RELEASE.md, Monitor and Verify).Review findings not acted on
.soneeds too: the issue's evidence is libc only, and the claim made is about glibc. A non-libc library need would be a separate failure mode; not widened here.Departures from the plan
None of substance. The review added the fail-closed behaviour, the exit-code fix and the docs-drift test.