Skip to content

feat: consume prebuilt V8 archives in wheel CI, retire GCP runners - #12

Closed
imfing wants to merge 1 commit into
feat/abi3-wheelsfrom
feat/consume-v8-archive
Closed

imfing wants to merge 1 commit into
feat/abi3-wheelsfrom
feat/consume-v8-archive

Conversation

@imfing

@imfing imfing commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Stacked on #9 (base branch feat/abi3-wheels; retarget to main / merge after #9). This is the final piece of the prebuilt-V8 plan: wheel builds stop compiling V8 and the GCP machinery leaves the repo.

Summary

  • Linux wheels build on free GitHub-hosted runners: x86_64 on ubuntu-latest, aarch64 natively on ubuntu-24.04-arm — both inside manylinux_2_28 containers via maturin-action. Expected build time: minutes (just the Rust crate; no V8 compile).
  • Prebuilt V8 consumption: the linux job derives the v8 version from Cargo.lock, downloads src_binding_release_{target}.rs from the librusty_v8-v{version} release, and points RUSTY_V8_ARCHIVE (URL) + RUSTY_V8_SRC_BINDING_PATH at the assets. A missing archive release fails loudly with instructions to run the Build V8 archive workflow — the forcing function after any v8 bump.
  • aarch64 wheel tests run natively on ubuntu-24.04-arm (the QEMU-in-docker test path is gone).
  • Deleted: GCP provision/cleanup jobs, startup.sh, build-manylinux-wheels.sh. (GCP_* secrets/Workload Identity are no longer referenced and can be cleaned up.)
  • Added verify-v8-archive workflow (manual dispatch): whole-archive -Wl,-z,defs link test under real glibc 2.28 proving archive linkability — missing symbols must all be first-party Rust FFI (temporal_rs_/rusty_v8_/v8__/v8_inspector__/cppgc__/crdtp__, provided by cargo at the real link); anything else fails. Validated green on the current archive: run 36933430748 — resulting .so requires at most GLIBC_2.28.

Prerequisites already in place

Release flow after this merges

  1. Tag push → wheels build in minutes on free runners, single cp310-abi3 wheel per platform (with feat: build abi3 wheels with pyo3 abi3-py310 feature #9), tested across Python 3.10–3.14 on both arches.
  2. On a deno_core/v8 bump → wheel CI fails pointing at the missing archive → dispatch Build V8 archive once (~1.5h, free) → done.

Verification notes

End-to-end wheel-build verification requires this workflow to run (workflow_dispatch on CI is available post-merge, or trigger via a pre-release tag). The constituent pieces are individually proven: the archive links under glibc 2.28 (verify workflow), RUSTY_V8_ARCHIVE/RUSTY_V8_SRC_BINDING_PATH are honored by rusty_v8's build script (source-verified for v150), and maturin-action mounts the workspace at an identical path in-container with RUST*-prefixed env forwarded (plus explicit -e flags).

Wheel builds now run entirely on free GitHub-hosted runners:
- x86_64 wheels on ubuntu-latest, aarch64 wheels natively on
  ubuntu-24.04-arm (no more QEMU), both inside manylinux_2_28
  containers via maturin-action.
- The prebuilt librusty_v8 static library + src binding are downloaded
  from the librusty_v8-v{version} release (version derived from
  Cargo.lock) and consumed via RUSTY_V8_ARCHIVE /
  RUSTY_V8_SRC_BINDING_PATH, so wheel builds no longer compile V8.
  A missing archive release fails loudly with instructions to run the
  'Build V8 archive' workflow.
- aarch64 wheel tests run natively on arm runners instead of QEMU.
- GCP spot-VM provisioning (provision/cleanup jobs, startup.sh) and
  the from-source wheel build script are removed.
- Add verify-v8-archive workflow (manual dispatch): whole-archive
  -z,defs link test under real glibc 2.28 proving archive linkability
  (first-party Rust FFI symbols stubbed, anything else fails).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant