Build PerfSpect from source and decouple it from the agent build - #84
Open
artursarlo wants to merge 5 commits into
Open
artursarlo wants to merge 5 commits into
artursarlo wants to merge 5 commits into
Conversation
Switch the executable build scripts to build PerfSpect from source (--strategy=build) instead of downloading the prebuilt release, and patch the freshly cloned PerfSpect source in build_perfspect.sh so it builds cleanly against the pinned revision on restricted hosts: - avx-turbo: full single-branch clone so the pinned commit is reachable (the shallow --depth 1 clone cannot check it out) - tools build: lower parallelism to -j4 to avoid GitHub throttling the many parallel anonymous git clones - make check: drop check_vuln so the build is not gated on CVEs disclosed after the pinned release Replace the manual docker build steps with a call to builder/build.sh and extract the arch-appropriate binary from the dist tarball into perfspect/perfspect (handling the root-owned artifact from the container). Co-authored-by: Cursor <cursoragent@cursor.com>
scripts/build_perfspect.sh clones PerfSpect into ./perfspect at build time (130MB+, contains root-owned artifacts from the container build). Ignore it so it can't be committed accidentally. Co-authored-by: Cursor <cursoragent@cursor.com>
PerfSpect can only be built on x86_64 (it cross-compiles both arches), so building it inline during the aarch64 executable build is not possible. Decouple it: the x86_64 and aarch64 executable build scripts no longer call build_perfspect.sh. Instead they accept a prebuilt PerfSpect binary via --perfspect <path> and stage it into the build context at perfspect/perfspect. If no binary is provided, the PerfSpect COPY is dropped and the agent is built without the resource (non-breaking for existing callers). This lets CI build PerfSpect once on an x86_64 worker and pass the per-arch artifact to each executable build. Co-authored-by: Cursor <cursoragent@cursor.com>
…erfile
build_perfspect.sh:
- Drop the --arch selector. 'make dist' cross-compiles both architectures, so
always extract both binaries (perfspect/perfspect-x86_64 and
perfspect/perfspect-aarch64) via a shared extract helper.
- Download strategy stays x86_64-only (Intel publishes no aarch64 release).
build_{x86_64,aarch64}_executable.sh:
- Stop wiping perfspect/. Stage only the single resource file perfspect/perfspect,
collision-safe (skip self-copy) with a sudo fallback for a root-owned stale file,
so prebuilt binaries left in perfspect/ by build_perfspect.sh are preserved.
- Never mutate the tracked executable.Dockerfile. When no --perfspect is given,
build from a throwaway temp Dockerfile with the PerfSpect COPY stripped, so a
missing perfspect/ can't break the build and runs are idempotent.
.dockerignore:
- Exclude perfspect/** except perfspect/perfspect, so the large clone/dist and the
per-arch binaries stay out of the build context now that perfspect/ isn't wiped.
Co-authored-by: Cursor <cursoragent@cursor.com>
builder/build.sh runs 'make dist' in a container as root with the clone bind-mounted, so dist/ and the in-container-built perfspect / perfspect-aarch64 binaries end up owned by root on the host. This made extracting perfspect-aarch64 fail (cp could not overwrite the root-owned file) and left root-owned artifacts behind. chown -R the tree back to the current user after the build, and make the extract helper overwrite its destination (rm -f before cp) so it no longer collides with the perfspect-aarch64 binary that make compiles at the clone root. Co-authored-by: Cursor <cursoragent@cursor.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Build the PerfSpect profiling tool from source with gProfiler-specific patches, and decouple it from the per-architecture agent executable builds so it can be built once (on x86_64) and passed in as a prebuilt binary.
Motivation
PerfSpect's
make distonly runs on x86_64 — it cross-compiles both the x86_64 and aarch64 binaries. Building it inline during theaarch64executable build is therefore impossible. Decoupling lets CI build PerfSpect once on an x86_64 worker and hand the right artifact to each architecture's build.Changes
scripts/build_perfspect.sh--depth 1clone couldn't check it out).make toolsparallelism to avoid GitHub clone throttling.check_vulnfrom the aggregatechecktarget so the build isn't gated on newly-disclosed CVEs.builder/build.sh.--archselector:make distcross-compiles both arches, so the script now always emits bothperfspect/perfspect-x86_64andperfspect/perfspect-aarch64.make distruns as root and leaves root-owned artifacts).scripts/build_x86_64_executable.sh/scripts/build_aarch64_executable.sh--perfspect <path>to bundle a prebuilt PerfSpect binary; if omitted, the agent is built without the resource (graceful, non-breaking).perfspect/perfspect(collision-safe), without wipingperfspect/, so prebuilt binaries produced alongside are preserved.executable.Dockerfile: when PerfSpect is absent, build from a throwaway Dockerfile with theCOPYstripped, keeping the tree clean and each run idempotent..dockerignore/.gitignoreperfspect/perfspectis shipped)./perfspect/build clone directory.Testing
x86_64 and aarch64 executable builds were validated manually end-to-end using the decoupled flow (
build_perfspect.sh --strategy buildproducing both binaries, then eachbuild_*_executable.sh --perfspect <binary>).Made with Cursor