Skip to content

CI: test on ppc64le, on a ppc64le runner as pyca/cryptography does - #97

Open
alex wants to merge 9 commits into
mainfrom
claude/cool-hamilton-crn96s-ci
Open

alex wants to merge 9 commits into
mainfrom
claude/cool-hamilton-crn96s-ci

Conversation

@alex

@alex alex commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

First step of #55 (ppc64le). This PR only adds CI. The ISA model and the algorithms follow in their own PRs, stacked on this one (#108 → #109 → #110 → #111 / #117).

What

This adds a platform to the rust job's matrix. It runs the Rust tests natively on ppc64le and exports coverage there, using the same runner and image pair as pyca/cryptography's distros job:

- {IMAGE: "ubuntu-rolling:ppc64le", NOXSESSION: "tests", RUNNER: "ubuntu-24.04-ppc64le"}

That is, runs-on: ubuntu-24.04-ppc64le with container: ghcr.io/pyca/cryptography-runner-ubuntu-rolling:ppc64le. IBM has approved the repo, and the job runs and passes.

Rust installation: since Rust 1.99.0 (released 2026-10-01), rustup toolchain install stable can't upgrade the toolchain preinstalled in pyca's runner images ("failure removing component … share/man/man1/cargo.1"). The ppc64le job therefore uses a fresh RUSTUP_HOME=/tmp/verified-garbage-rustup, which installs the toolchain rather than upgrading it. That is the same fix #458 makes for the ARMv7 job, which fails the same way on main. This PR also carries #458's change to the ARMv7 matrix entry, so its CI is green whichever of the two lands first. The text is identical, so they merge cleanly.

The ppc64le build and the checks need a few small changes:

  • src/cpu.rs: no module chooses among implementations on PPC64LE yet, so with -D warnings the ppc64le build rejected the CPU detection as dead code. This adds an allow(dead_code) for PPC64LE only. The ChaCha20 PR (ChaCha20 on PPC64LE: verified block function and keystream XOR #109) removes it again, since ChaCha20's backend selection uses the detection.

  • ci/check_arch_gates.py: ARCHES (all architectures, for a file with no cfg) gets powerpc64. The files that named no architecture, but whose library code doesn't run on PPC64LE, now name the four it does run on:

    • the RFC 1321 tests and tests/acvp/mldsa.rs, the ML-DSA test macros, which use SHA-3;
    • the benchmarks of ChaCha20, HMAC-SHA-256, MD5, SHA-1, SHA-256 and SHA-512.

    Each algorithm's PPC64LE PR widens its gate again.

  • ci/bench_arches.py: PPC64LE isn't benchmarked. A change to src/asm/powerpc64le/ used to fall through to the shared src/ rule, which benchmarked every module on every other architecture. Assembly of an architecture that isn't benchmarked now needs no benchmark.

Stable only

An exclude drops the 1.88 job for ppc64le, because inline assembly on PowerPC (and so naked_asm!) was only stabilized in Rust 1.95. I checked this locally: 1.94 rejects naked_asm! on powerpc64le-unknown-linux-gnu with E0658 ("inline assembly is not stable yet on this architecture"), and 1.95 through the current stable accept it. Once the ppc64le assembly lands, building for ppc64le needs Rust ≥ 1.95, even though rust-version stays 1.88 for the other targets. Whether to raise the MSRV instead is up to you.

Testing

All of the following pass locally on this branch merged with main (39aa9f4):

  • cargo fmt
  • cargo clippy --all-targets -D warnings, on the host and cross-built for powerpc64le-unknown-linux-gnu
  • cargo test under qemu-ppc64le with RUSTFLAGS=-D warnings
  • the bench crate's clippy
  • ci/check_arch_gates.py, check_variants.py, algorithms_table.py --check and check_vectors.py

🤖 Generated with Claude Code

https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE

@alex

alex commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

Please do this as a regular part of the matrix + an exclude

@alex

alex commented Sep 28, 2026

Copy link
Copy Markdown
Member Author

Also needs IBM to approve this repo.

@alex
alex marked this pull request as draft September 28, 2026 11:31
@alex
alex force-pushed the claude/cool-hamilton-crn96s-ci branch from 8aee5fe to 311d0db Compare September 28, 2026 12:14
@alex
alex force-pushed the claude/cool-hamilton-crn96s-ci branch 2 times, most recently from 9995ffe to c25f58f Compare September 29, 2026 23:02
@alex
alex marked this pull request as ready for review October 1, 2026 01:45
@alex
alex added this pull request to the merge queue Oct 1, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 1, 2026
@alex

alex commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Please rebase this

claude added 5 commits October 1, 2026 02:20
The job runs in pyca's ppc64le runner image (ghcr.io/pyca/cryptography-runner-ubuntu-rolling:ppc64le)
on the ubuntu-24.04-ppc64le runner, the same pair pyca/cryptography's
distros job uses. It runs on stable only: inline assembly on PowerPC,
which the verified code needs for naked_asm!, was stabilized in Rust
1.95, after the crate's minimum of 1.88.

Refs #55

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
No PPC64LE module chooses among implementations yet, so with -D warnings
the ppc64le build rejected cpu.rs's detection as dead code.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
PPC64LE is not benchmarked, and a change to its generated assembly only
fell through to the shared src/ rule, which benchmarked every module on
every other architecture.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
ci/check_arch_gates.py's ARCHES (all architectures, for a file with no
cfg) gets powerpc64. The RFC 1321 tests and the benchmarks of ChaCha20,
HMAC-SHA-256, MD5, SHA-1, SHA-256 and SHA-512, which named no
architecture, now name the four their library code runs on, so the tests
build on ppc64le and the check holds; each algorithm's PR for PPC64LE
widens its gate again.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
tests/acvp/mldsa.rs (new on main) names no architecture, so with powerpc64
in check_arch_gates.py's ARCHES it would be built for PPC64LE, where
hashes::sha3 (which its macro uses) is not. Gate it on SHA-3's
architectures; the parameter sets' files that expand it are gated already.

Refs #55

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
@alex
alex force-pushed the claude/cool-hamilton-crn96s-ci branch from c25f58f to 7e23749 Compare October 1, 2026 02:20

alex commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Rebased onto current main (d71927b). One addition: tests/acvp/mldsa.rs, which landed on main after this PR's last CI run, names no architecture. With powerpc64 in ARCHES, ci/check_arch_gates.py would fail on it, so it now has the same four-architecture gate as SHA-3, which its macro uses (the mldsa44/65/87.rs files that expand it are gated already). cargo fmt, clippy (host, ppc64le and the bench crate), cargo test under qemu-ppc64le, and the arch-gate, variant, vector, bench and table checks pass locally.


Generated by Claude Code

claude added 4 commits October 1, 2026 13:13
…up home

Since Rust 1.99.0 (2026-10-01), `rustup toolchain install stable` fails in
pyca's runner images: updating the image's preinstalled toolchain removes
its previous components, and the image's installation lacks files their
manifests list ("failure removing component 'cargo-...', directory does not
exist: 'share/man/man1/cargo.1'"). The ARMv7 job on main fails the same
way; #458 fixes it by pointing RUSTUP_HOME at a fresh directory, so that
the toolchain is installed rather than upgraded. Do the same for the ppc64le
platform (and its 1.88 exclusion, which must match it), and carry #458's
ARMv7 change so that this PR's CI is green whichever lands first.

Refs #55

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
The Thumb job (new on main) runs in the same ARMv7 image, and fails to
upgrade its preinstalled stable toolchain to 1.99.0 in the same way; #458
gives it a fresh RUSTUP_HOME too. Carry that change here as well, so this
PR's CI is green whichever lands first.

Refs #55

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
The ARMv7 benchmark job runs in the same image as ci.yml's ARMv7 jobs, and
fails to upgrade its preinstalled stable toolchain to 1.99.0 in the same
way ("failure removing component 'cargo-...', directory does not exist:
'share/man/man1/cargo.1'"). Point it at a fresh RUSTUP_HOME too.

Refs #55

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fw6RULWHCeVgMDGc3wRrwE
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

2 participants