Repository navigation
244 lines (215 loc) · 9.46 KB
/
Copy pathbuild-pycurl.yml
File metadata and controls
244 lines (215 loc) · 9.46 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
# SPDX-FileCopyrightText: 2026 The RISE Project
# SPDX-License-Identifier: MIT
---
# Based on the `package-wheel` job of
# https://github.com/pycurl/pycurl/blob/v7.47.0/.github/workflows/cibuildwheel.yml
name: Build pycurl wheels (riscv64)
on:
workflow_dispatch:
inputs:
version:
description: 'Version glob to (re)build; empty builds every version of docs/packages/pycurl.yaml not released yet'
required: false
default: ''
pull_request:
branches: [main]
paths:
- '.github/workflows/build-pycurl.yml'
- 'docs/packages/pycurl.yaml'
push:
branches: [main]
paths:
- '.github/workflows/build-pycurl.yml'
- 'docs/packages/pycurl.yaml'
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true
permissions:
contents: read # to fetch code (actions/checkout)
env:
MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64
jobs:
setup:
uses: $/.github/workflows/_setup.yml
with:
package: pycurl
version: ${{ inputs.version }}
build_wheels:
needs: [setup]
if: needs.setup.outputs.versions != '[]'
name: Build pycurl ${{ matrix.version }} ${{ matrix.python }}-manylinux_riscv64
runs-on: ubuntu-24.04-riscv
timeout-minutes: 90
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
python: ["cp310", "cp311", "cp312", "cp313", "cp314", "cp314t"]
env:
PYCURL_VERSION: ${{ matrix.version }}
steps:
- name: Checkout pycurl v${{ env.PYCURL_VERSION }}
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: pycurl/pycurl
ref: v${{ env.PYCURL_VERSION }}
persist-credentials: false
- name: Checkout python-wheels
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
path: python-wheels
persist-credentials: false
- name: Patch pycurl source
run: git apply python-wheels/patches/pycurl/${{ env.PYCURL_VERSION }}/00*.patch
- name: Stage the licence-collection script
run: |
cat > collect-licenses.sh <<'COLLECT_EOF'
#!/bin/bash
# SPDX-FileCopyrightText: 2026 The RISE Project
# SPDX-License-Identifier: MIT
#
# Stage, at the project root, the licence of every shared library
# auditwheel vendors out of the build image alongside libcurl.
# setuptools' widened LICENSE.* glob (see the patch) copies them into the wheel.
set -euo pipefail
project="${1:?usage: collect-licenses.sh <project-dir>}"
# ldd is transitive, so libcurl.so alone covers its whole closure;
# ldd does not list the root itself, so resolve that too.
mapfile -t libs < <(
{
ldd /usr/lib64/libcurl.so | tr ' ' '\n' | grep '^/'
readlink -f /usr/lib64/libcurl.so
} | sort -u
)
# `rpm -qf` reports unowned files on stdout, so keep only bare package names.
# glibc, the gcc runtime and zlib are on auditwheel's manylinux allowlist and
# are never vendored into the wheel.
mapfile -t pkgs < <(
rpm -qf --qf '%{NAME}\n' "${libs[@]}" 2>/dev/null |
grep -E '^[A-Za-z0-9._+-]+$' | sort -u |
grep -vE '^(glibc|libgcc|libstdc\+\+|gcc|zlib-ng-compat)$'
)
for pkg in "${pkgs[@]}"; do
mapfile -t files < <(rpm -q --licensefiles "$pkg" 2>/dev/null || true)
# Some subpackages leave the licence to a sibling of the same source RPM.
if [ -z "${files[0]:-}" ]; then
srpm=$(rpm -q --qf '%{SOURCERPM}\n' "$pkg")
mapfile -t files < <(
rpm -qa --qf '%{SOURCERPM} %{NAME}\n' |
awk -v s="$srpm" '$1 == s { print $2 }' |
xargs -r rpm -q --licensefiles 2>/dev/null | sort -u
)
fi
# Others mark it %doc rather than %license, and the image installs no docs.
if [ -z "${files[0]:-}" ]; then
dnf -y --disablerepo=extras reinstall --setopt=tsflags= "$pkg" >/dev/null
mapfile -t files < <(rpm -qd "$pkg" | grep -iE '/(LICEN[CS]E|COPYING|NOTICE)')
fi
for f in "${files[@]}"; do
[ -f "$f" ] || continue
cp "$f" "$project/LICENSE.${pkg}.$(basename "$f")"
done
compgen -G "$project/LICENSE.$pkg.*" >/dev/null ||
{ echo "no licence file found for $pkg" >&2; exit 1; }
done
ls -1 "$project"/LICENSE.* | sed "s|$project/||"
COLLECT_EOF
- name: Build wheels
uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0
with:
output-dir: wheelhouse/
only: ${{ matrix.python }}-manylinux_riscv64
env:
CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }}
# Replaces upstream's vcpkg before-all: the riscv64 image's own
# libcurl-devel (appstream, not EPEL - gotcha 51) is a full build of
# curl, so no source build is needed.
CIBW_BEFORE_ALL_LINUX: >-
dnf install -y libcurl-devel &&
bash {project}/collect-licenses.sh {project}
CIBW_ENVIRONMENT: >-
PYCURL_SSL_LIBRARY=openssl
PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/
# paramiko's cryptography/bcrypt deps have no riscv64 wheel below cp312;
# fall back to the rest of the dev requirements so its sftp tests, which are
# pytest.importorskip'd, skip instead of failing metadata generation.
CIBW_BEFORE_TEST_LINUX: >-
pip install flake8 -r {package}/requirements-dev.txt ||
{ grep -v '^paramiko' {package}/requirements-dev.txt > /tmp/requirements-dev.txt &&
pip install flake8 -r /tmp/requirements-dev.txt; } &&
make -C {package}/tests/fake-curl/libcurl
CIBW_TEST_COMMAND: pytest -v -ra {project}/tests
- name: Verify the wheel ships the compiled extension and licences
run: |
python3 - wheelhouse/*.whl <<'EOF'
import sys, zipfile
names = zipfile.ZipFile(sys.argv[1]).namelist()
sos = sorted(n for n in names if n.endswith(".so"))
print("\n".join(sos))
assert any("pycurl/_pycurl." in n for n in sos), sos
lic = sorted(n.split("/")[-1] for n in names if ".dist-info/licenses/" in n and not n.endswith("/"))
print("\n".join(lic))
expected_pkgs = {
"cyrus-sasl-lib", "keyutils-libs", "krb5-libs", "libbrotli", "libcap",
"libcbor", "libcom_err", "libcurl", "libevent", "libfido2", "libidn2",
"libnghttp2", "libpsl", "libselinux", "libssh", "libunistring",
"libxcrypt", "openldap", "openssl-libs", "pcre2", "systemd-libs",
}
have_pkgs = {f.split(".", 2)[1] for f in lic if f.startswith("LICENSE.")}
assert {"COPYING-LGPL", "COPYING-MIT"} <= set(lic), lic
assert expected_pkgs <= have_pkgs, expected_pkgs - have_pkgs
EOF
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: pycurl-${{ env.PYCURL_VERSION }}-${{ matrix.python }}-manylinux_riscv64
path: ./wheelhouse/*.whl
if-no-files-found: error
gpl_sources:
needs: [setup]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
name: Collect GPL sources for pycurl ${{ matrix.version }}
runs-on: ubuntu-24.04-riscv
env:
PYCURL_VERSION: ${{ matrix.version }}
steps:
- name: Checkout python-wheels
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
# keyutils-libs/libcap/libidn2/libssh/libunistring/libxcrypt/pcre2/systemd-libs
# are the copyleft (GPL/LGPL) libraries auditwheel vendors out of the build
# image alongside libcurl; the rest of the closure is permissively licensed.
- uses: ./actions/collect-gpl-sources
with:
image: ${{ env.MANYLINUX_RISCV64_IMAGE }}
packages: >-
gcc keyutils-libs libcap libidn2 libssh libunistring libxcrypt
pcre2 systemd-libs
output: gpl-sources.tar
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: pycurl-${{ env.PYCURL_VERSION }}-gpl-sources
path: gpl-sources.tar
if-no-files-found: error
publish:
name: Publish pycurl ${{ matrix.version }}
needs: [setup, build_wheels, gpl_sources]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
permissions:
contents: write
pull-requests: write
uses: $/.github/workflows/_publish-wheel.yml
secrets:
app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }}
with:
artifact-pattern: pycurl-${{ matrix.version }}-*-manylinux_riscv64
gpl-sources-artifact: pycurl-${{ matrix.version }}-gpl-sources
gpl-sources-description: gcc and the copyleft libraries bundled in the wheel