Skip to content

ray-haproxy: Add version 2.8.25 #8

ray-haproxy: Add version 2.8.25

ray-haproxy: Add version 2.8.25 #8

# SPDX-FileCopyrightText: 2026 The RISE Project
# SPDX-License-Identifier: MIT
---
# This workflow is based on:
# https://github.com/ray-project/ray-haproxy/blob/v2.8.25/.github/workflows/release.yml
name: Build ray-haproxy wheels (riscv64)
on:
workflow_dispatch:
inputs:
version:
description: 'Version glob to (re)build; empty builds every version of docs/packages/ray-haproxy.yaml not released yet'
required: false
default: ''
pull_request:
branches: [main]
paths:
- '.github/workflows/build-ray-haproxy.yml'
- 'docs/packages/ray-haproxy.yaml'
- 'patches/ray-haproxy/**'
push:
branches: [main]
paths:
- '.github/workflows/build-ray-haproxy.yml'
- 'docs/packages/ray-haproxy.yaml'
- 'patches/ray-haproxy/**'
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true
permissions:
contents: read # to fetch code (actions/checkout)
env:
MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64
jobs:
setup:
uses: $/.github/workflows/_setup.yml
with:
package: ray-haproxy
version: ${{ inputs.version }}
build_wheel:
needs: [setup]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
name: Build ray-haproxy ${{ matrix.version }} py3-none-manylinux_riscv64
runs-on: ubuntu-24.04-riscv
timeout-minutes: 60
env:
RAY_HAPROXY_VERSION: ${{ matrix.version }}
HAPROXY_VERSION: ${{ matrix.version }}
steps:
- name: Checkout ray-haproxy v${{ matrix.version }}
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: ray-project/ray-haproxy
ref: v${{ env.RAY_HAPROXY_VERSION }}
persist-credentials: false
- name: Checkout python-wheels
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
path: python-wheels
persist-credentials: false
- name: Apply patches
run: git apply -v python-wheels/patches/ray-haproxy/${{ env.RAY_HAPROXY_VERSION }}/*.patch
# Upstream's own build step, run against manylinux_2_39_riscv64 instead of
# manylinux2014 (which has no riscv64 image), then packaged the same way
# its release.yml does outside the container.
- name: Build HAProxy and package the wheel
run: |
docker run --rm \
-v "$(pwd)":/workspace \
--workdir /workspace \
-e HAPROXY_VERSION \
-e OUTPUT_DIR=/workspace/dist \
"${{ env.MANYLINUX_RISCV64_IMAGE }}" \
bash -c '
set -euxo pipefail
./ci/build/build-haproxy-dist.sh
mkdir -p ray_haproxy/bin/lib
tar -xzf dist/haproxy-linux-riscv64.tar.gz -C ray_haproxy/bin/
/opt/python/cp312-cp312/bin/python -m pip install -q wheel setuptools
/opt/python/cp312-cp312/bin/python setup.py bdist_wheel --plat-name manylinux_2_39_riscv64
'
- name: Verify the wheel ships the riscv64 binary
run: |
python3 - dist/*.whl <<'EOF'
import sys, zipfile
with zipfile.ZipFile(sys.argv[1]) as zf:
names = zf.namelist()
print("\n".join(names))
binary = next(n for n in names if n.endswith("ray_haproxy/bin/haproxy"))
header = zf.read(binary)[:20]
assert header[:4] == b"\x7fELF", header
assert header[18] == 0xF3, header # e_machine == EM_RISCV
libs = [n for n in names if "ray_haproxy/bin/lib/" in n and not n.endswith("lib/")]
assert libs, "no vendored shared libraries in the wheel"
licenses = sorted(n.rsplit("/", 1)[-1] for n in names if ".data/data/" in n)
assert licenses == ["LICENSE", "THIRD_PARTY_LICENSES"], licenses
EOF
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ray-haproxy-${{ env.RAY_HAPROXY_VERSION }}-py3-none-manylinux_riscv64
path: dist/*.whl
if-no-files-found: error
test_wheel:
name: Test ray-haproxy ${{ matrix.version }} on Python ${{ matrix.python-version }}
needs: [setup, build_wheel]
if: needs.setup.outputs.versions != '[]'
runs-on: ubuntu-24.04-riscv
timeout-minutes: 30
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
# Upstream tests 3.9-3.12; trimmed to the interpreters this registry targets.
python-version: ['3.12', '3.13', '3.14']
env:
RAY_HAPROXY_VERSION: ${{ matrix.version }}
steps:
# Checked out beside the workspace root (not into it) so the package's
# own ray_haproxy/ source directory can't shadow the installed wheel
# when the smoke test below imports ray_haproxy (gotcha 187).
- name: Checkout ray-haproxy v${{ matrix.version }} (tests)
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: ray-project/ray-haproxy
ref: v${{ env.RAY_HAPROXY_VERSION }}
path: ray-haproxy-src
persist-credentials: false
- name: Checkout python-wheels
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
path: python-wheels
persist-credentials: false
- name: Apply patches
run: git -C ray-haproxy-src apply -v ../python-wheels/patches/ray-haproxy/${{ env.RAY_HAPROXY_VERSION }}/*.patch
- name: Download wheel
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: ray-haproxy-${{ env.RAY_HAPROXY_VERSION }}-py3-none-manylinux_riscv64
path: wheelhouse
- name: Install Python
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
with:
python-version: ${{ matrix.python-version }}
activate-environment: true
enable-cache: false
- name: Install the wheel
run: uv pip install --reinstall --no-index --find-links wheelhouse ray-haproxy
- name: Run upstream's smoke test
run: |
python -c "
from ray_haproxy import get_haproxy_binary
import subprocess, sys
binary = get_haproxy_binary()
print(f'Python {sys.version}')
print(f'Binary: {binary}')
result = subprocess.run([binary, '-v'], capture_output=True, text=True)
print(result.stdout or result.stderr)
assert result.returncode == 0, f'haproxy -v failed: {result.returncode}'
print('OK')
"
# Runs upstream's own vendoring checker (RPATH, ldd resolution, ELF
# sanity) directly on real riscv64 hardware, in place of upstream's
# `verify` job, which spins up six distro containers, several of
# which (amazonlinux, rockylinux:9) have no riscv64 image to run.
- name: Run upstream's vendoring verification
run: |
BINARY="$(python -c 'from ray_haproxy import get_haproxy_binary; print(get_haproxy_binary())')"
chmod +x ray-haproxy-src/ci/verify-vendoring.sh
ray-haproxy-src/ci/verify-vendoring.sh "$BINARY" "$(dirname "$BINARY")/lib"
gpl_sources:
needs: [setup]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
name: Collect GPL sources for ray-haproxy ${{ matrix.version }}
runs-on: ubuntu-24.04-riscv
env:
RAY_HAPROXY_VERSION: ${{ matrix.version }}
steps:
- name: Checkout python-wheels
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- uses: ./actions/collect-gpl-sources
with:
image: ${{ env.MANYLINUX_RISCV64_IMAGE }}
packages: gcc
output: gpl-sources.tar
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ray-haproxy-${{ env.RAY_HAPROXY_VERSION }}-gpl-sources
path: gpl-sources.tar
if-no-files-found: error
publish:
name: Publish ray-haproxy ${{ matrix.version }}
needs: [setup, build_wheel, test_wheel, gpl_sources]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
permissions:
contents: write
pull-requests: write
uses: $/.github/workflows/_publish-wheel.yml
secrets:
app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }}
with:
artifact-pattern: ray-haproxy-${{ matrix.version }}-py3-none-manylinux_riscv64
gpl-sources-artifact: ray-haproxy-${{ matrix.version }}-gpl-sources
gpl-sources-description: gcc