Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions .github/workflows/build-docker-images.yml
Original file line number Diff line number Diff line change
Expand Up @@ -129,6 +129,15 @@ jobs:
NODE24_ARCH_RELEASE=${{ env.NODE24_ARCH_RELEASE }}
${{ matrix.IMAGE.BUILD_ARGS }}
outputs: ${{ ((github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch') && github.ref == 'refs/heads/main') && 'type=registry,compression=zstd' || 'type=docker' }}
- name: Check Rust component manifests
if: matrix.IMAGE.DOCKERFILE_PATH == 'runners/ubuntu'
run: |
# Exercise the uninstall path even if stable has not changed since
# the image was built. This container is disposable.
docker run --rm \
--pull=${{ github.ref == 'refs/heads/main' && github.event_name != 'pull_request' && 'always' || 'never' }} \
ghcr.io/pyca/${{ matrix.IMAGE.TAG_NAME }} \
rustup component remove cargo llvm-tools-preview rustc rust-std
- uses: actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8 # v4.2.2
with:
subject-name: "ghcr.io/pyca/${{ steps.image-name.outputs.ATTEST_IMAGE }}"
Expand Down
18 changes: 9 additions & 9 deletions runners/ubuntu/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@ ENV DEBIAN_FRONTEND=noninteractive
# "ANSI_X3.4-1968".
ENV LANG=C.UTF-8

# Docker overlay filesystems can reject directory renames during toolchain
# updates with EXDEV. Allow rustup to copy the files in that case.
ENV RUSTUP_PERMIT_COPY_RENAME=1

# Don't unpack things nothing in CI uses: static libpython and OpenSSL, gcc's
# LTO backend, and the sanitizer runtimes (hard deps of libgcc-dev).
RUN printf '%s\n' \
Expand Down Expand Up @@ -64,13 +68,13 @@ RUN if [ "$(readelf -h /proc/self/exe | grep -o 'Machine:.* ARM')" ]; \

RUN python3 -m venv /venv && /venv/bin/pip install -U pip wheel --no-cache-dir

# We only need llvm-profdata and llvm-cov from llvm-tools-preview (for rust
# coverage). Its libLLVM.so is identical to rustc's, so symlink it, then strip
# the big binaries (with llvm-strip; GNU strip breaks them) and drop the rest.
# Deduplicate libLLVM and strip the big binaries (with llvm-strip; GNU strip
# breaks them). Keep all files recorded in rustup's component manifests:
# deleting even unused files prevents rustup from uninstalling or updating
# the toolchain.
RUN curl -sSf https://sh.rustup.rs -o /tmp/rustup-init.sh && \
sh /tmp/rustup-init.sh -y --default-toolchain stable --profile minimal --component llvm-tools-preview && \
rm /tmp/rustup-init.sh && \
rm -rf /root/.rustup/toolchains/*/share/doc /root/.rustup/toolchains/*/share/man && \
sysroot="$(/root/.cargo/bin/rustc --print sysroot)" && \
host="$(/root/.cargo/bin/rustc -vV | sed -n 's/^host: //p')" && \
cd "$sysroot/lib/rustlib/$host" && \
Expand All @@ -84,9 +88,5 @@ RUN curl -sSf https://sh.rustup.rs -o /tmp/rustup-init.sh && \
/root/.cargo/bin/rustup \
bin/rust-lld bin/llvm-cov bin/llvm-profdata; do \
if [ -f "$f" ]; then bin/llvm-strip --strip-all "$f"; fi; \
done && \
for f in $(sed -n "s|^file:lib/rustlib/$host/bin/||p" "$sysroot/lib/rustlib/manifest-llvm-tools-preview-$host"); do \
case "$f" in llvm-cov|llvm-profdata) ;; *) rm "bin/$f" ;; esac; \
done && \
rm -f lib/librustc-stable_rt.*.a bin/wasm-component-ld
done
ENV PATH="/root/.cargo/bin:$PATH"
Loading