Skip to content

Commit 863cb9e

Browse files
committed
python-olm: Add version 3.2.16
Add the riscv64 wheel build for python-olm 3.2.16, the cffi bindings for libolm, Matrix's Olm/Megolm cryptographic ratchet. The sdist job mirrors upstream's own make_sdist.sh (the released PyPI sdist is byte-identical in file list), and the wheel job builds that sdist with cibuildwheel on the riscv64 manylinux image. libolm's CMakeLists declares cmake_minimum_required(VERSION 3.4), below CMake 4's floor, so the build carries CMAKE_POLICY_VERSION_MINIMUM=3.5. The wheel carried no licence text at all; a patch adds libolm's Apache-2.0 LICENSE and curve25519-donna's BSD-3-Clause notice.
1 parent c7d0836 commit 863cb9e

3 files changed

Lines changed: 233 additions & 0 deletions

File tree

Lines changed: 171 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,171 @@
1+
# SPDX-FileCopyrightText: 2026 The RISE Project
2+
# SPDX-License-Identifier: MIT
3+
---
4+
# Based on the `dist:python:sdist`/`dist:python:wheel` jobs of
5+
# https://gitlab.matrix.org/matrix-org/olm/-/blob/3.2.16/python/.gitlab-ci.yml
6+
name: Build python-olm wheels (riscv64)
7+
8+
on:
9+
workflow_dispatch:
10+
inputs:
11+
version:
12+
description: 'Version glob to (re)build; empty builds every version of docs/packages/python-olm.yaml not released yet'
13+
required: false
14+
default: ''
15+
pull_request:
16+
branches: [main]
17+
paths:
18+
- '.github/workflows/build-python-olm.yml'
19+
- 'docs/packages/python-olm.yaml'
20+
push:
21+
branches: [main]
22+
paths:
23+
- '.github/workflows/build-python-olm.yml'
24+
- 'docs/packages/python-olm.yaml'
25+
26+
concurrency:
27+
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
28+
cancel-in-progress: true
29+
30+
permissions:
31+
contents: read # to fetch code (actions/checkout)
32+
33+
env:
34+
MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64
35+
36+
jobs:
37+
setup:
38+
uses: $/.github/workflows/_setup.yml
39+
with:
40+
package: python-olm
41+
version: ${{ inputs.version }}
42+
43+
build_sdist:
44+
needs: [setup]
45+
if: needs.setup.outputs.versions != '[]'
46+
name: Build python-olm ${{ matrix.version }} sdist
47+
runs-on: ubuntu-latest
48+
strategy:
49+
fail-fast: false
50+
matrix:
51+
version: ${{ fromJSON(needs.setup.outputs.versions) }}
52+
53+
env:
54+
PYTHON_OLM_VERSION: ${{ matrix.version }}
55+
56+
steps:
57+
# olm is hosted on gitlab.matrix.org, which actions/checkout cannot reach.
58+
- name: Checkout olm ${{ env.PYTHON_OLM_VERSION }}
59+
run: |
60+
git clone --depth 1 --branch "${{ env.PYTHON_OLM_VERSION }}" \
61+
https://gitlab.matrix.org/matrix-org/olm.git olm-src
62+
63+
- name: Checkout python-wheels
64+
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
65+
with:
66+
path: python-wheels
67+
persist-credentials: false
68+
69+
- name: Patch olm source
70+
working-directory: olm-src
71+
run: |
72+
git apply ../python-wheels/patches/python-olm/${{ env.PYTHON_OLM_VERSION }}/00*.patch
73+
74+
- name: setup uv
75+
uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
76+
with:
77+
python-version: '3.12'
78+
activate-environment: true
79+
enable-cache: false
80+
81+
# The cffi hook runs olm_build.py, and so libolm's cmake build, even for
82+
# an sdist; libolm asks for cmake 3.4, below the floor of cmake 4.
83+
- name: Build sdist
84+
working-directory: olm-src/python
85+
env:
86+
CMAKE_POLICY_VERSION_MINIMUM: '3.5'
87+
run: |
88+
uv pip install build
89+
./make_sdist.sh
90+
91+
- name: Upload sdist artifact
92+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
93+
with:
94+
name: python-olm-${{ env.PYTHON_OLM_VERSION }}-sdist
95+
path: olm-src/python/dist/*.tar.gz
96+
if-no-files-found: error
97+
98+
build_wheels:
99+
needs: [setup, build_sdist]
100+
if: needs.setup.outputs.versions != '[]'
101+
name: Build python-olm ${{ matrix.version }} ${{ matrix.python }}-manylinux_riscv64
102+
runs-on: ubuntu-24.04-riscv
103+
timeout-minutes: 120
104+
strategy:
105+
fail-fast: false
106+
matrix:
107+
version: ${{ fromJSON(needs.setup.outputs.versions) }}
108+
python: ["cp312", "cp313", "cp314", "cp314t"]
109+
110+
env:
111+
PYTHON_OLM_VERSION: ${{ matrix.version }}
112+
113+
steps:
114+
# The sdist ships no tests; the suite only exists in the git tree.
115+
- name: Checkout olm ${{ env.PYTHON_OLM_VERSION }} tests
116+
run: |
117+
git clone --depth 1 --branch "${{ env.PYTHON_OLM_VERSION }}" \
118+
https://gitlab.matrix.org/matrix-org/olm.git olm-src
119+
mv olm-src/python/tests tests
120+
121+
- name: Fetch sdist artifact
122+
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
123+
with:
124+
name: python-olm-${{ env.PYTHON_OLM_VERSION }}-sdist
125+
path: dist
126+
127+
- id: sdist_dir
128+
run: |
129+
tar zxf dist/*.tar.gz -C dist
130+
echo "path=$(echo dist/python_olm-*/)" >> "$GITHUB_OUTPUT"
131+
132+
- name: Build wheels
133+
uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0
134+
with:
135+
package-dir: ${{ steps.sdist_dir.outputs.path }}
136+
output-dir: wheelhouse/
137+
env:
138+
CIBW_ARCHS: riscv64
139+
CIBW_BUILD: ${{ matrix.python }}-manylinux_riscv64
140+
CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }}
141+
# cffi has no riscv64 wheel on PyPI.
142+
CIBW_ENVIRONMENT: >-
143+
PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/
144+
CMAKE_POLICY_VERSION_MINIMUM=3.5
145+
CIBW_TEST_REQUIRES: pytest pytest-benchmark aspectlib
146+
CIBW_TEST_SOURCES: tests
147+
CIBW_TEST_COMMAND: python -m pytest tests --benchmark-disable
148+
149+
- name: Store wheels
150+
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
151+
with:
152+
name: python-olm-${{ env.PYTHON_OLM_VERSION }}-${{ matrix.python }}-manylinux_riscv64
153+
path: wheelhouse/*.whl
154+
if-no-files-found: error
155+
156+
publish:
157+
name: Publish python-olm ${{ matrix.version }}
158+
needs: [setup, build_wheels]
159+
if: needs.setup.outputs.versions != '[]'
160+
strategy:
161+
fail-fast: false
162+
matrix:
163+
version: ${{ fromJSON(needs.setup.outputs.versions) }}
164+
permissions:
165+
contents: write
166+
pull-requests: write
167+
uses: $/.github/workflows/_publish-wheel.yml
168+
secrets:
169+
app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }}
170+
with:
171+
artifact-pattern: python-olm-${{ matrix.version }}-*-manylinux_riscv64

‎docs/packages/python-olm.yaml‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
package-name: python-olm
2+
source-code: https://gitlab.matrix.org/matrix-org/olm
3+
license: Apache-2.0
4+
versions:
5+
- version: 3.2.16
6+
patched: true
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
From be65e6ef1e2a0d0e0186947bff0620ada84df7ba Mon Sep 17 00:00:00 2001
2+
From: Ludovic Henry <git@ludovic.dev>
3+
Date: Mon, 21 Sep 2026 11:57:35 +0000
4+
Subject: [PATCH] ship libolm's licences with the wheel
5+
6+
Upstream-Status: To upstream [libolm is deprecated upstream and its last commit predates this; the same gap exists in every python-olm wheel on PyPI]
7+
8+
The extension statically links the whole of libolm (Apache-2.0) together with
9+
the bundled curve25519-donna (BSD-3-Clause), whose terms both require their
10+
notice to travel with a binary redistribution. Neither reaches the wheel:
11+
make_sdist.sh never copies the repository's LICENSE into the sdist, so
12+
setuptools' default license-file glob finds nothing and the built wheel ships
13+
no notice at all.
14+
15+
Copy LICENSE beside the generated headers and name both files explicitly, so
16+
setuptools keeps each entry's path relative to the project root and they land
17+
in the wheel as dist-info/licenses/LICENSE and
18+
dist-info/licenses/libolm/lib/curve25519-donna/LICENSE.md.
19+
20+
The other vendored sources compiled in, Brad Conte's crypto-algorithms and the
21+
ref10-derived ed25519, are both public domain and ask for no notice.
22+
23+
Signed-off-by: Ludovic Henry <git@ludovic.dev>
24+
---
25+
python/make_sdist.sh | 1 +
26+
python/setup.cfg | 5 +++++
27+
2 files changed, 6 insertions(+)
28+
29+
diff --git a/python/make_sdist.sh b/python/make_sdist.sh
30+
index 7f90fdb..7fbfd68 100755
31+
--- a/python/make_sdist.sh
32+
+++ b/python/make_sdist.sh
33+
@@ -15,6 +15,7 @@ mkdir -p libolm
34+
echo "Cleaning sources"
35+
make clean > /dev/null
36+
cp -a $SRC/include .
37+
+cp -a $SRC/../LICENSE .
38+
echo "Copying libolm sources"
39+
for src in cmake CMakeLists.txt common.mk include lib Makefile olm.pc.in src tests; do
40+
cp -a $SRC/../$src libolm
41+
diff --git a/python/setup.cfg b/python/setup.cfg
42+
index 1be5f25..a886abc 100644
43+
--- a/python/setup.cfg
44+
+++ b/python/setup.cfg
45+
@@ -3,3 +3,8 @@ testpaths = tests
46+
flake8-ignore =
47+
olm/*.py F401
48+
tests/*.py W503
49+
+
50+
+[metadata]
51+
+license_files =
52+
+ LICENSE
53+
+ libolm/lib/curve25519-donna/LICENSE.md
54+
--
55+
2.43.0
56+

0 commit comments

Comments
 (0)