Repository navigation
feat: consume prebuilt V8 archives in wheel CI, retire GCP runners - #13
Merged
Merged
Conversation
Wheel builds now run entirely on free GitHub-hosted runners:
- x86_64 wheels on ubuntu-latest, aarch64 wheels natively on
ubuntu-24.04-arm (no more QEMU), both inside manylinux_2_28
containers via maturin-action.
- The prebuilt librusty_v8 static library + src binding are downloaded
from the librusty_v8-v{version} release (version derived from
Cargo.lock) and consumed via RUSTY_V8_ARCHIVE /
RUSTY_V8_SRC_BINDING_PATH, so wheel builds no longer compile V8.
A missing archive release fails loudly with instructions to run the
'Build V8 archive' workflow.
- aarch64 wheel tests run natively on arm runners instead of QEMU.
- GCP spot-VM provisioning (provision/cleanup jobs, startup.sh) and
the from-source wheel build script are removed.
- Add verify-v8-archive workflow (manual dispatch): whole-archive
-z,defs link test under real glibc 2.28 proving archive linkability
(first-party Rust FFI symbols stubbed, anything else fails).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #12. Final piece of the prebuilt-V8 plan (#10 → #11 → this).
Why
Every release recompiled all of V8, requiring a 32-core GCP spot VM. But V8 only changes when
Cargo.lockbumps it (3–4×/yr). Split the cadences: compile V8 once per bump, let wheel builds link the prebuilt archive on free runners.flowchart LR subgraph before ["Before: every release"] T1[tag push] --> P[provision GCP VM] --> B1[compile V8] --> W1[build wheels] end subgraph after ["After"] V8bump[v8 bump] -->|dispatch, ~1.5h| AR[Build V8 archive] --> REL[("librusty_v8-v{ver} release")] T2[tag push] -->|minutes| W2[build wheels] REL -.->|RUSTY_V8_ARCHIVE| W2 endMechanism
A v8 bump self-enforces: wheel CI fails with instructions until the archive workflow runs once.
Blast radius
ubuntu-24.04-armstartup.sh, old wheel scriptGCP_*secrets can be removed)Also adds
verify-v8-archive(manual dispatch): whole-archive-z,defslink test under real glibc 2.28.Evidence & risk
Archive linkability proven: green verify run — the linked
.soneeds at mostGLIBC_2.28; all stubbed symbols are first-party Rust FFI (same set as denoland's prebuilts), provided by cargo at the real link. Assets onlibrusty_v8-v150.4.0are symbol-audited at build time.Residual: the full wheel path hasn't run end-to-end yet (needs this workflow on a dispatchable ref) — smoke-test with
workflow_dispatchfrom main before the next release tag.