Skip to content

fix(developer-rust): add LLVM, PGO and BOLT as standard - #105

Merged
catinspace-au merged 2 commits into
mainfrom
fix/rust-llvm-pgo-bolt
Oct 6, 2026
Merged

catinspace-au merged 2 commits into
mainfrom
fix/rust-llvm-pgo-bolt

Conversation

@catinspace-au

@catinspace-au catinspace-au commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

LLVM, clang, lld and BOLT are now standard in the Rust role, so cross-language LTO, bindgen, PGO and post-link optimisation work on every Rust box without hand setup. Re-apply just this part with --tags rust-llvm.

  • rust_llvm_version picks the major: latest (default, the newest llvmorg release tag, 23 today), rustc (the major rustc was built with) or a pinned integer.
  • llvm-profdata and llvm-cov still come from rustup's llvm-tools component, now on rustup Macs too, because those must match rustc's LLVM exactly.
  • Ubuntu: apt.llvm.org's versioned suite only, never the unversioned dev snapshot, which would hijack clang with the 24 snapshot. The key must be the single pinned key before anything trusts it, and it lands at /usr/share/keyrings/llvm.gpg, the same path hyperi-ci uses.
    • Any other source for the same suite is detected (hyperi-ci's llvm.list, or a line from upstream's llvm.sh). The conflicting line is removed only after our source is written. If the install fails, the previous source and lines are restored and apt is checked clean.
    • /usr/local/bin gets clang, clang++, ld.lld, llvm-bolt, merge-fdata and perf2bolt links to the chosen major. A real file or a link we do not own is left alone and reported.
  • Fedora installs its distro LLVM (22 on F44, 21 on F43) and warns while that sits below what rustc needs for LTO. macOS uses brew's llvm and lld.
  • The toolchain post-condition now also checks the host target's cargo linker exists, on PATH or in the rustc sysroot.

Tested in ubuntu:24.04, ubuntu:26.04 and fedora:44, covering latest and pinned majors, idempotence, and two-key and wrong-fingerprint files failing closed. Also tested: an llvm.sh-style source both with a failed install (fully restored, apt clean) and on a successful run, a foreign deb822 for the same suite, a failed major switch rolling back, and a real file at /usr/local/bin/clang left alone. macOS is syntax-checked only.

Done when a Rust box has clang, lld and BOLT at the configured major and apt stays clean whatever else configured apt.llvm.org.

developer-rust now installs clang, lld, BOLT and the LLVM dev files as standard, so cross-language LTO, bindgen, PGO and post-link optimisation work on every Rust box without hand setup. Re-apply just this part with --tags rust-llvm.

rust_llvm_version picks the major: latest (default, the newest llvmorg release tag), rustc (the major rustc was built with) or a pinned integer. llvm-profdata and llvm-cov still come from rustup's llvm-tools component, now installed on rustup Macs too, because those must match rustc's LLVM exactly.

Ubuntu takes apt.llvm.org's versioned suite only, never the unversioned dev snapshot. The key is fingerprint-checked before anything trusts it and lands in /usr/share/keyrings/llvm.gpg, the same path hyperi-ci uses, and a duplicate line for the same suite in hyperi-ci's llvm.list is dropped. /usr/local/bin gets clang, clang++, ld.lld, llvm-bolt, merge-fdata and perf2bolt links to the chosen major, ahead of hyperi-rust-setup so the cargo linker resolves to it. A real file or a foreign link at those paths is left alone and reported.

Fedora installs its distro LLVM (compat packages for an older pin) and warns while it sits below the requested major. macOS installs brew's keg-only llvm and lld. Every failure lands in deploy_warnings rather than stopping the run, and the toolchain post-condition now also fails a converge whose cargo config names a linker that does not exist.
apt refuses to read any source list once one URI and suite carries two different Signed-By values, and upstream's llvm.sh writes exactly such a line. The role now finds every other entry for the suite it is about to add, drops the one-line ones only after its own source is written, and stands aside with a warning when someone else's deb822 file already owns the suite. A failed run puts our source and any edited list back as it found them and checks apt-get update reads cleanly, so a switch to a major whose packages are missing leaves the old major installable.

The key file must now hold exactly one primary key with the pinned fingerprint, because dearmoring trusts every key in the file. The pinned value is compared without spaces and in upper case.

The host linker post-condition now checks only the host target's linker and also looks in the rustc sysroot, so rust-lld and an uninstalled cross linker no longer fail a converge. The drift warning only claims cross-language LTO breaks when the system LLVM is older than rustc's; an unavailable pin gets its own warning and trailing latest is a debug note. Also: per-host latest resolution, 023 read as 23, no lld@N below 19 on macOS, the highest brew keg version, previous-major removal after the links move, no warnings from check mode, and corrected lld keg-only text.
@catinspace-au catinspace-au changed the title fix(developer-rust): LLVM, PGO and BOLT as standard fix(developer-rust): add LLVM, PGO and BOLT as standard Oct 6, 2026
@catinspace-au
catinspace-au merged commit d95ad82 into main Oct 6, 2026
24 of 25 checks passed
@catinspace-au
catinspace-au deleted the fix/rust-llvm-pgo-bolt branch October 6, 2026 03:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant