From 973ee24224b47edad86e419047d0b3bb9ebd1d4c Mon Sep 17 00:00:00 2001 From: Paul Kehrer Date: Thu, 1 Oct 2026 21:08:23 +0800 Subject: [PATCH 1/2] Preserve rustup-managed files in Ubuntu runner images --- .github/workflows/build-docker-images.yml | 9 +++++++++ runners/ubuntu/Dockerfile | 14 +++++--------- 2 files changed, 14 insertions(+), 9 deletions(-) diff --git a/.github/workflows/build-docker-images.yml b/.github/workflows/build-docker-images.yml index e5bf912..5798ea3 100644 --- a/.github/workflows/build-docker-images.yml +++ b/.github/workflows/build-docker-images.yml @@ -129,6 +129,15 @@ jobs: NODE24_ARCH_RELEASE=${{ env.NODE24_ARCH_RELEASE }} ${{ matrix.IMAGE.BUILD_ARGS }} outputs: ${{ ((github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main') && 'type=registry,compression=zstd' || 'type=docker' }} + - name: Check Rust component manifests + if: matrix.IMAGE.DOCKERFILE_PATH == 'runners/ubuntu' + run: | + # Exercise the uninstall path even if stable has not changed since + # the image was built. This container is disposable. + docker run --rm \ + --pull=${{ github.ref == 'refs/heads/main' && github.event_name != 'pull_request' && 'always' || 'never' }} \ + ghcr.io/pyca/${{ matrix.IMAGE.TAG_NAME }} \ + rustup component remove cargo llvm-tools-preview rustc rust-std - uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2 with: subject-name: "ghcr.io/pyca/${{ steps.image-name.outputs.ATTEST_IMAGE }}" diff --git a/runners/ubuntu/Dockerfile b/runners/ubuntu/Dockerfile index 5f01689..e407c7d 100644 --- a/runners/ubuntu/Dockerfile +++ b/runners/ubuntu/Dockerfile @@ -64,13 +64,13 @@ RUN if [ "$(readelf -h /proc/self/exe | grep -o 'Machine:.* ARM')" ]; \ RUN python3 -m venv /venv && /venv/bin/pip install -U pip wheel --no-cache-dir -# We only need llvm-profdata and llvm-cov from llvm-tools-preview (for rust -# coverage). Its libLLVM.so is identical to rustc's, so symlink it, then strip -# the big binaries (with llvm-strip; GNU strip breaks them) and drop the rest. +# Deduplicate libLLVM and strip the big binaries (with llvm-strip; GNU strip +# breaks them). Keep all files recorded in rustup's component manifests: +# deleting even unused files prevents rustup from uninstalling or updating +# the toolchain. RUN curl -sSf https://sh.rustup.rs -o /tmp/rustup-init.sh && \ sh /tmp/rustup-init.sh -y --default-toolchain stable --profile minimal --component llvm-tools-preview && \ rm /tmp/rustup-init.sh && \ - rm -rf /root/.rustup/toolchains/*/share/doc /root/.rustup/toolchains/*/share/man && \ sysroot="$(/root/.cargo/bin/rustc --print sysroot)" && \ host="$(/root/.cargo/bin/rustc -vV | sed -n 's/^host: //p')" && \ cd "$sysroot/lib/rustlib/$host" && \ @@ -84,9 +84,5 @@ RUN curl -sSf https://sh.rustup.rs -o /tmp/rustup-init.sh && \ /root/.cargo/bin/rustup \ bin/rust-lld bin/llvm-cov bin/llvm-profdata; do \ if [ -f "$f" ]; then bin/llvm-strip --strip-all "$f"; fi; \ - done && \ - for f in $(sed -n "s|^file:lib/rustlib/$host/bin/||p" "$sysroot/lib/rustlib/manifest-llvm-tools-preview-$host"); do \ - case "$f" in llvm-cov|llvm-profdata) ;; *) rm "bin/$f" ;; esac; \ - done && \ - rm -f lib/librustc-stable_rt.*.a bin/wasm-component-ld + done ENV PATH="/root/.cargo/bin:$PATH" From 52831b58af9bb651216e2995bbea3b398180d875 Mon Sep 17 00:00:00 2001 From: Paul Kehrer Date: Fri, 2 Oct 2026 14:38:53 +0800 Subject: [PATCH 2/2] Allow rustup toolchain updates on Docker overlay filesystems --- runners/ubuntu/Dockerfile | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/runners/ubuntu/Dockerfile b/runners/ubuntu/Dockerfile index e407c7d..c2357f8 100644 --- a/runners/ubuntu/Dockerfile +++ b/runners/ubuntu/Dockerfile @@ -10,6 +10,10 @@ ENV DEBIAN_FRONTEND=noninteractive # "ANSI_X3.4-1968". ENV LANG=C.UTF-8 +# Docker overlay filesystems can reject directory renames during toolchain +# updates with EXDEV. Allow rustup to copy the files in that case. +ENV RUSTUP_PERMIT_COPY_RENAME=1 + # Don't unpack things nothing in CI uses: static libpython and OpenSSL, gcc's # LTO backend, and the sanitizer runtimes (hard deps of libgcc-dev). RUN printf '%s\n' \