Skip to content

feat: consume prebuilt V8 archives in wheel CI, retire GCP runners - #13

Merged
imfing merged 1 commit into
mainfrom
feat/consume-v8-archive
Oct 3, 2026
Merged

imfing merged 1 commit into
mainfrom
feat/consume-v8-archive

Conversation

@imfing

@imfing imfing commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Supersedes #12. Final piece of the prebuilt-V8 plan (#10 → #11 → this).

Why

Every release recompiled all of V8, requiring a 32-core GCP spot VM. But V8 only changes when Cargo.lock bumps it (3–4×/yr). Split the cadences: compile V8 once per bump, let wheel builds link the prebuilt archive on free runners.

flowchart LR
    subgraph before ["Before: every release"]
        T1[tag push] --> P[provision GCP VM] --> B1[compile V8] --> W1[build wheels]
    end
    subgraph after ["After"]
        V8bump[v8 bump] -->|dispatch, ~1.5h| AR[Build V8 archive] --> REL[("librusty_v8-v{ver} release")]
        T2[tag push] -->|minutes| W2[build wheels]
        REL -.->|RUSTY_V8_ARCHIVE| W2
    end
Loading

Mechanism

version = parse Cargo.lock ["v8"]                  # 150.4.0
download src_binding from librusty_v8-v{version}   # missing? fail: "run Build V8 archive"
maturin build --manylinux 2_28 with:
    RUSTY_V8_ARCHIVE          = {release url}/librusty_v8_release_{target}.a.gz
    RUSTY_V8_SRC_BINDING_PATH = .v8/src_binding_release_{target}.rs

A v8 bump self-enforces: wheel CI fails with instructions until the archive workflow runs once.

Blast radius

Area Impact
Linux wheel builds Rewritten — free runners (x86_64 + native arm64), prebuilt archive, no V8 compile
aarch64 wheel tests QEMU → native ubuntu-24.04-arm
GCP jobs, startup.sh, old wheel script Deleted (GCP_* secrets can be removed)
macOS / sdist / release / publish, runtime code, wheel contents Untouched
Rollback Revert this commit; archive releases are additive

Also adds verify-v8-archive (manual dispatch): whole-archive -z,defs link test under real glibc 2.28.

Evidence & risk

Archive linkability proven: green verify run — the linked .so needs at most GLIBC_2.28; all stubbed symbols are first-party Rust FFI (same set as denoland's prebuilts), provided by cargo at the real link. Assets on librusty_v8-v150.4.0 are symbol-audited at build time.

Residual: the full wheel path hasn't run end-to-end yet (needs this workflow on a dispatchable ref) — smoke-test with workflow_dispatch from main before the next release tag.

Wheel builds now run entirely on free GitHub-hosted runners:
- x86_64 wheels on ubuntu-latest, aarch64 wheels natively on
  ubuntu-24.04-arm (no more QEMU), both inside manylinux_2_28
  containers via maturin-action.
- The prebuilt librusty_v8 static library + src binding are downloaded
  from the librusty_v8-v{version} release (version derived from
  Cargo.lock) and consumed via RUSTY_V8_ARCHIVE /
  RUSTY_V8_SRC_BINDING_PATH, so wheel builds no longer compile V8.
  A missing archive release fails loudly with instructions to run the
  'Build V8 archive' workflow.
- aarch64 wheel tests run natively on arm runners instead of QEMU.
- GCP spot-VM provisioning (provision/cleanup jobs, startup.sh) and
  the from-source wheel build script are removed.
- Add verify-v8-archive workflow (manual dispatch): whole-archive
  -z,defs link test under real glibc 2.28 proving archive linkability
  (first-party Rust FFI symbols stubbed, anything else fails).
@imfing
imfing merged commit 5358242 into main Oct 3, 2026
@imfing
imfing deleted the feat/consume-v8-archive branch October 3, 2026 11:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant