diff --git a/.github/workflows/build-ray-haproxy.yml b/.github/workflows/build-ray-haproxy.yml new file mode 100644 index 00000000000..4808bf58c06 --- /dev/null +++ b/.github/workflows/build-ray-haproxy.yml @@ -0,0 +1,245 @@ +# SPDX-FileCopyrightText: 2026 The RISE Project +# SPDX-License-Identifier: MIT +--- +# This workflow is based on: +# https://github.com/ray-project/ray-haproxy/blob/v2.8.25/.github/workflows/release.yml +name: Build ray-haproxy wheels (riscv64) + +on: + workflow_dispatch: + inputs: + version: + description: 'Version glob to (re)build; empty builds every version of docs/packages/ray-haproxy.yaml not released yet' + required: false + default: '' + pull_request: + branches: [main] + paths: + - '.github/workflows/build-ray-haproxy.yml' + - 'docs/packages/ray-haproxy.yaml' + - 'patches/ray-haproxy/**' + push: + branches: [main] + paths: + - '.github/workflows/build-ray-haproxy.yml' + - 'docs/packages/ray-haproxy.yaml' + - 'patches/ray-haproxy/**' + +concurrency: + group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +permissions: + contents: read # to fetch code (actions/checkout) + +env: + MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64 + +jobs: + setup: + uses: $/.github/workflows/_setup.yml + with: + package: ray-haproxy + version: ${{ inputs.version }} + + build_wheel: + needs: [setup] + if: needs.setup.outputs.versions != '[]' + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + name: Build ray-haproxy ${{ matrix.version }} py3-none-manylinux_riscv64 + runs-on: ubuntu-24.04-riscv + timeout-minutes: 60 + + env: + RAY_HAPROXY_VERSION: ${{ matrix.version }} + HAPROXY_VERSION: ${{ matrix.version }} + + steps: + - name: Checkout ray-haproxy v${{ matrix.version }} + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: ray-project/ray-haproxy + ref: v${{ env.RAY_HAPROXY_VERSION }} + persist-credentials: false + + - name: Checkout python-wheels + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + path: python-wheels + persist-credentials: false + + - name: Apply patches + run: git apply -v python-wheels/patches/ray-haproxy/${{ env.RAY_HAPROXY_VERSION }}/*.patch + + # Upstream's own build step, run against manylinux_2_39_riscv64 instead of + # manylinux2014 (which has no riscv64 image), then packaged the same way + # its release.yml does outside the container. + - name: Build HAProxy and package the wheel + run: | + docker run --rm \ + -v "$(pwd)":/workspace \ + --workdir /workspace \ + -e HAPROXY_VERSION \ + -e OUTPUT_DIR=/workspace/dist \ + "${{ env.MANYLINUX_RISCV64_IMAGE }}" \ + bash -c ' + set -euxo pipefail + ./ci/build/build-haproxy-dist.sh + mkdir -p ray_haproxy/bin/lib + tar -xzf dist/haproxy-linux-riscv64.tar.gz -C ray_haproxy/bin/ + /opt/python/cp312-cp312/bin/python -m pip install -q wheel setuptools + /opt/python/cp312-cp312/bin/python setup.py bdist_wheel --plat-name manylinux_2_39_riscv64 + ' + + - name: Verify the wheel ships the riscv64 binary + run: | + python3 - dist/*.whl <<'EOF' + import sys, zipfile + with zipfile.ZipFile(sys.argv[1]) as zf: + names = zf.namelist() + print("\n".join(names)) + binary = next(n for n in names if n.endswith("ray_haproxy/bin/haproxy")) + header = zf.read(binary)[:20] + assert header[:4] == b"\x7fELF", header + assert header[18] == 0xF3, header # e_machine == EM_RISCV + libs = [n for n in names if "ray_haproxy/bin/lib/" in n and not n.endswith("lib/")] + assert libs, "no vendored shared libraries in the wheel" + licenses = sorted(n.rsplit("/", 1)[-1] for n in names if ".data/data/" in n) + assert licenses == ["LICENSE", "THIRD_PARTY_LICENSES"], licenses + EOF + + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: ray-haproxy-${{ env.RAY_HAPROXY_VERSION }}-py3-none-manylinux_riscv64 + path: dist/*.whl + if-no-files-found: error + + test_wheel: + name: Test ray-haproxy ${{ matrix.version }} on Python ${{ matrix.python-version }} + needs: [setup, build_wheel] + if: needs.setup.outputs.versions != '[]' + runs-on: ubuntu-24.04-riscv + timeout-minutes: 30 + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + # Upstream tests 3.9-3.12; trimmed to the interpreters this registry targets. + python-version: ['3.12', '3.13', '3.14'] + + env: + RAY_HAPROXY_VERSION: ${{ matrix.version }} + + steps: + # Checked out beside the workspace root (not into it) so the package's + # own ray_haproxy/ source directory can't shadow the installed wheel + # when the smoke test below imports ray_haproxy (gotcha 187). + - name: Checkout ray-haproxy v${{ matrix.version }} (tests) + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: ray-project/ray-haproxy + ref: v${{ env.RAY_HAPROXY_VERSION }} + path: ray-haproxy-src + persist-credentials: false + + - name: Checkout python-wheels + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + path: python-wheels + persist-credentials: false + + - name: Apply patches + run: git -C ray-haproxy-src apply -v "$GITHUB_WORKSPACE"/python-wheels/patches/ray-haproxy/${{ env.RAY_HAPROXY_VERSION }}/*.patch + + - name: Download wheel + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: ray-haproxy-${{ env.RAY_HAPROXY_VERSION }}-py3-none-manylinux_riscv64 + path: wheelhouse + + - name: Install Python + uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + with: + python-version: ${{ matrix.python-version }} + activate-environment: true + enable-cache: false + + - name: Install the wheel + run: uv pip install --reinstall --no-index --find-links wheelhouse ray-haproxy + + - name: Run upstream's smoke test + run: | + python -c " + from ray_haproxy import get_haproxy_binary + import subprocess, sys + binary = get_haproxy_binary() + print(f'Python {sys.version}') + print(f'Binary: {binary}') + result = subprocess.run([binary, '-v'], capture_output=True, text=True) + print(result.stdout or result.stderr) + assert result.returncode == 0, f'haproxy -v failed: {result.returncode}' + print('OK') + " + + # Runs upstream's own vendoring checker (RPATH, ldd resolution, ELF + # sanity) directly on real riscv64 hardware, in place of upstream's + # `verify` job, which spins up six distro containers, several of + # which (amazonlinux, rockylinux:9) have no riscv64 image to run. + - name: Run upstream's vendoring verification + run: | + BINARY="$(python -c 'from ray_haproxy import get_haproxy_binary; print(get_haproxy_binary())')" + chmod +x ray-haproxy-src/ci/verify-vendoring.sh + ray-haproxy-src/ci/verify-vendoring.sh "$BINARY" "$(dirname "$BINARY")/lib" + + gpl_sources: + needs: [setup] + if: needs.setup.outputs.versions != '[]' + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + name: Collect GPL sources for ray-haproxy ${{ matrix.version }} + runs-on: ubuntu-24.04-riscv + + env: + RAY_HAPROXY_VERSION: ${{ matrix.version }} + + steps: + - name: Checkout python-wheels + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + persist-credentials: false + + - uses: ./actions/collect-gpl-sources + with: + image: ${{ env.MANYLINUX_RISCV64_IMAGE }} + packages: gcc libxcrypt + output: gpl-sources.tar + + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: ray-haproxy-${{ env.RAY_HAPROXY_VERSION }}-gpl-sources + path: gpl-sources.tar + if-no-files-found: error + + publish: + name: Publish ray-haproxy ${{ matrix.version }} + needs: [setup, build_wheel, test_wheel, gpl_sources] + if: needs.setup.outputs.versions != '[]' + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + permissions: + contents: write + pull-requests: write + uses: $/.github/workflows/_publish-wheel.yml + secrets: + app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }} + with: + artifact-pattern: ray-haproxy-${{ matrix.version }}-py3-none-manylinux_riscv64 + gpl-sources-artifact: ray-haproxy-${{ matrix.version }}-gpl-sources + gpl-sources-description: gcc and the copyleft libraries bundled in the wheel diff --git a/docs/packages/ray-haproxy.yaml b/docs/packages/ray-haproxy.yaml new file mode 100644 index 00000000000..a9ae875bac0 --- /dev/null +++ b/docs/packages/ray-haproxy.yaml @@ -0,0 +1,5 @@ +package-name: ray-haproxy +source-code: https://github.com/ray-project/ray-haproxy +license: GNU General Public License v2 (GPLv2) +versions: +- version: 2.8.25 diff --git a/patches/ray-haproxy/2.8.25/0001-build-haproxy-dist-add-riscv64-and-build-against-PC.patch b/patches/ray-haproxy/2.8.25/0001-build-haproxy-dist-add-riscv64-and-build-against-PC.patch new file mode 100644 index 00000000000..b6d2832c7b9 --- /dev/null +++ b/patches/ray-haproxy/2.8.25/0001-build-haproxy-dist-add-riscv64-and-build-against-PC.patch @@ -0,0 +1,83 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Ludovic Henry +Date: Mon, 28 Sep 2026 00:00:00 +0000 +Subject: [PATCH] ci/build: add riscv64 and build against PCRE2 there + +build-haproxy-dist.sh's arch normalisation only knows x86_64/aarch64/arm64, +so it exits with "Unsupported architecture: riscv64" before doing anything: + + Unsupported architecture: riscv64 + +Add a riscv64 case. Its dependency install and HAProxy `make` flags also +assume PCRE1 (`pcre-devel`, `USE_PCRE=1`), which manylinux2014 (CentOS 7) +carries; manylinux_2_39_riscv64 (Rocky 10) dropped the legacy PCRE1 package +and only ships `pcre2-devel`. Branch on the riscv64 arch label to install +`pcre2-devel` and build with `USE_PCRE2=1 USE_PCRE2_JIT=1` instead, leaving +the x86_64/aarch64 codepath untouched. + +Rocky 10 also splits `FindBin.pm` out of its base Perl into `perl-FindBin`, +which OpenSSL's `Configure` needs and manylinux2014's Perl carries without +a separate package: + + Can't locate FindBin.pm in @INC (you may need to install the FindBin module) ... at .../openssl-3.0.15/Configure line 15. + +Rocky 10 splits the `lib` pragma out the same way, into `perl-lib`, and +`Configure` needs that too (it's `use`d two lines later than `FindBin`, so +this only surfaced once the FindBin install let Configure get further): + + Can't locate lib.pm in @INC (you may need to install the lib module) ... at .../openssl-3.0.15/Configure line 16. + +Install both alongside `perl-IPC-Cmd` on riscv64. + +Upstream-Status: Inappropriate [manylinux2014 (x86_64/aarch64) still has pcre-devel; this is a difference between manylinux images, not something upstream's existing targets need] + +Signed-off-by: Ludovic Henry +--- +diff --git a/ci/build/build-haproxy-dist.sh b/ci/build/build-haproxy-dist.sh +--- a/ci/build/build-haproxy-dist.sh ++++ b/ci/build/build-haproxy-dist.sh +@@ -62,6 +62,7 @@ + x86_64) ARCH_LABEL="x86_64" ;; + aarch64) ARCH_LABEL="arm64" ;; + arm64) ARCH_LABEL="arm64" ;; # macOS (future) ++ riscv64) ARCH_LABEL="riscv64" ;; + *) echo "Unsupported architecture: $ARCH"; exit 1 ;; + esac + +@@ -91,7 +92,14 @@ + # lua-devel — for HAProxy USE_LUA=1 (Lua 5.1 on CentOS 7) + # --------------------------------------------------------------------------- + echo "==> Installing build dependencies" +-yum install -y perl-IPC-Cmd pcre-devel zlib-devel readline-devel 2>/dev/null ++if [ "$ARCH_LABEL" = "riscv64" ]; then ++ # manylinux_2_39_riscv64 (Rocky 10) dropped the legacy PCRE1 package; ++ # only pcre2-devel is available there. HAProxy's USE_PCRE2 build option ++ # is the equivalent for that library. ++ yum install -y perl-IPC-Cmd perl-FindBin perl-lib pcre2-devel zlib-devel readline-devel 2>/dev/null ++else ++ yum install -y perl-IPC-Cmd pcre-devel zlib-devel readline-devel 2>/dev/null ++fi + + # --------------------------------------------------------------------------- + # 1. Build OpenSSL from source +@@ -159,13 +167,19 @@ + tar -xzf "$BUILD_DIR/haproxy.tar.gz" -C "$BUILD_DIR" --strip-components=1 + + echo "==> Compiling HAProxy" ++# manylinux_2_39_riscv64 only has pcre2-devel (see the riscv64 branch above), ++# so build against PCRE2 there instead of PCRE1. ++PCRE_MAKE_VARS=(USE_PCRE=1) ++if [ "$ARCH_LABEL" = "riscv64" ]; then ++ PCRE_MAKE_VARS=(USE_PCRE2=1 USE_PCRE2_JIT=1) ++fi + make -C "$BUILD_DIR" \ + TARGET=linux-glibc \ + USE_OPENSSL=1 \ + SSL_INC="$DEPS_DIR/include" \ + SSL_LIB="$OPENSSL_LIB_DIR" \ + USE_ZLIB=1 \ +- USE_PCRE=1 \ ++ "${PCRE_MAKE_VARS[@]}" \ + USE_LUA=1 \ + LUA_INC="$DEPS_DIR/include" \ + LUA_LIB="$DEPS_DIR/lib" \ diff --git a/patches/ray-haproxy/2.8.25/0002-verify-vendoring-recognise-riscv64-binaries.patch b/patches/ray-haproxy/2.8.25/0002-verify-vendoring-recognise-riscv64-binaries.patch new file mode 100644 index 00000000000..7a17d711c4e --- /dev/null +++ b/patches/ray-haproxy/2.8.25/0002-verify-vendoring-recognise-riscv64-binaries.patch @@ -0,0 +1,28 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Ludovic Henry +Date: Mon, 28 Sep 2026 00:00:00 +0000 +Subject: [PATCH] ci: verify-vendoring: recognise riscv64 binaries + +The ELF sanity check only matches `file`'s output for x86-64 and aarch64, so +it fails a riscv64 binary that is otherwise fine: + + FAIL: Unexpected binary type: ELF 64-bit LSB pie executable, UCB RISC-V, ... + +Add a branch for `file`'s "RISC-V" architecture string. + +Upstream-Status: Inappropriate [only needed once a riscv64 leg exists to call this script; upstream's own x86_64/aarch64 legs never hit this path] + +Signed-off-by: Ludovic Henry +--- +diff --git a/ci/verify-vendoring.sh b/ci/verify-vendoring.sh +--- a/ci/verify-vendoring.sh ++++ b/ci/verify-vendoring.sh +@@ -128,6 +128,8 @@ + pass "Binary is ELF 64-bit x86-64" + elif echo "$FILE_TYPE" | grep -q "ELF 64-bit.*aarch64"; then + pass "Binary is ELF 64-bit aarch64" ++elif echo "$FILE_TYPE" | grep -q "ELF 64-bit.*RISC-V"; then ++ pass "Binary is ELF 64-bit RISC-V" + else + fail "Unexpected binary type: $FILE_TYPE" + fi diff --git a/patches/ray-haproxy/2.8.25/0003-THIRD_PARTY_LICENSES-note-PCRE2-on-riscv64.patch b/patches/ray-haproxy/2.8.25/0003-THIRD_PARTY_LICENSES-note-PCRE2-on-riscv64.patch new file mode 100644 index 00000000000..14edc099aa5 --- /dev/null +++ b/patches/ray-haproxy/2.8.25/0003-THIRD_PARTY_LICENSES-note-PCRE2-on-riscv64.patch @@ -0,0 +1,28 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Ludovic Henry +Date: Mon, 28 Sep 2026 00:00:00 +0000 +Subject: [PATCH] THIRD_PARTY_LICENSES: note PCRE2 on riscv64 + +The riscv64 build links PCRE2 (previous patch), not the classic PCRE1 this +file's "PCRE" entry names and links to (sourceforge.net/projects/pcre, +pcre.org). Both share the same BSD-style licence text already quoted here, +but point the Source line at PCRE2's own repo too so the notice matches what +the riscv64 wheel actually vendors. + +Upstream-Status: Inappropriate [only the riscv64 build in this fork links PCRE2; upstream's own x86_64/aarch64 wheels still vendor PCRE1] + +Signed-off-by: Ludovic Henry +--- +diff --git a/THIRD_PARTY_LICENSES b/THIRD_PARTY_LICENSES +--- a/THIRD_PARTY_LICENSES ++++ b/THIRD_PARTY_LICENSES +@@ -33,7 +33,9 @@ + PCRE (Perl Compatible Regular Expressions) + ------------------------------------------- + License: BSD License ++Note: the riscv64 wheel vendors PCRE2 instead; same licence. + Source: https://sourceforge.net/projects/pcre/ ++ https://github.com/PCRE2Project/pcre2 (PCRE2, riscv64) + https://www.pcre.org/ + + Redistribution and use in source and binary forms, with or without diff --git a/patches/ray-haproxy/2.8.25/0004-build-haproxy-dist-link-above-mmap_min_addr-on-riscv64.patch b/patches/ray-haproxy/2.8.25/0004-build-haproxy-dist-link-above-mmap_min_addr-on-riscv64.patch new file mode 100644 index 00000000000..f7f72b8f3df --- /dev/null +++ b/patches/ray-haproxy/2.8.25/0004-build-haproxy-dist-link-above-mmap_min_addr-on-riscv64.patch @@ -0,0 +1,57 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Ludovic Henry +Date: Thu, 1 Oct 2026 00:00:00 +0000 +Subject: [PATCH] ci/build: link haproxy above mmap_min_addr on riscv64 + +The staged binary is killed with SIGSEGV the first time the script runs +it, with no output from HAProxy or from the dynamic linker: + + Segmentation fault LD_LIBRARY_PATH="$STAGE_DIR/lib" "$STAGE_DIR/haproxy" -v + +HAProxy's Makefile links a non-PIE executable, and GNU ld's riscv64 +default linker script places its first PT_LOAD at 0x10000 (x86_64 and +aarch64 use 0x400000). `patchelf --set-rpath '$ORIGIN/lib'` has to grow +the program headers of an ET_EXEC it cannot relocate, so it maps them in +a new segment just below the old base, under 0x10000 -- which is the +kernel's vm.mmap_min_addr on the riscv64 runners. execve then fails past +its point of no return and the process dies before ld.so's first +instruction: LD_DEBUG=all writes nothing and LD_DEBUG_OUTPUT is never +even created, and ldd (which asks ld.so to load the binary) reports "not +a dynamic executable" for the patchelf'd file. The vendored libraries +play no part in it: the crash is identical whether Rocky 10's OpenSSL +3.5.5 or the OpenSSL 3.0.15 built here is vendored. + +Pass `-Wl,-Ttext-segment=0x200000` through HAProxy's ADDLIB link hook on +riscv64, so patchelf's extra segment still lands above mmap_min_addr, as +it already does on x86_64/aarch64 with their higher default base. + +Upstream-Status: Inappropriate [riscv64-only: x86_64/aarch64 link at 0x400000, so patchelf's prepended segment never drops below mmap_min_addr there] + +Signed-off-by: Ludovic Henry +--- +diff --git a/ci/build/build-haproxy-dist.sh b/ci/build/build-haproxy-dist.sh +--- a/ci/build/build-haproxy-dist.sh ++++ b/ci/build/build-haproxy-dist.sh +@@ -173,6 +173,14 @@ PCRE_MAKE_VARS=(USE_PCRE=1) + if [ "$ARCH_LABEL" = "riscv64" ]; then + PCRE_MAKE_VARS=(USE_PCRE2=1 USE_PCRE2_JIT=1) + fi ++# riscv64's default non-PIE link base is 0x10000, which is also the kernel's ++# vm.mmap_min_addr: the program header segment `patchelf --set-rpath` prepends ++# below it further down can't be mapped, and execve kills the binary with ++# SIGSEGV before ld.so runs. Link it higher, like x86_64/aarch64 already are. ++LINK_MAKE_VARS=() ++if [ "$ARCH_LABEL" = "riscv64" ]; then ++ LINK_MAKE_VARS=(ADDLIB=-Wl,-Ttext-segment=0x200000) ++fi + make -C "$BUILD_DIR" \ + TARGET=linux-glibc \ + USE_OPENSSL=1 \ +@@ -184,6 +192,7 @@ make -C "$BUILD_DIR" \ + LUA_INC="$DEPS_DIR/include" \ + LUA_LIB="$DEPS_DIR/lib" \ + USE_PROMEX=1 \ ++ "${LINK_MAKE_VARS[@]}" \ + -j"$(nproc)" + + # --------------------------------------------------------------------------- diff --git a/patches/ray-haproxy/2.8.25/0005-build-haproxy-dist-vendor-our-own-openssl-on-riscv64.patch b/patches/ray-haproxy/2.8.25/0005-build-haproxy-dist-vendor-our-own-openssl-on-riscv64.patch new file mode 100644 index 00000000000..97ae66eec84 --- /dev/null +++ b/patches/ray-haproxy/2.8.25/0005-build-haproxy-dist-vendor-our-own-openssl-on-riscv64.patch @@ -0,0 +1,54 @@ +From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001 +From: Ludovic Henry +Date: Thu, 1 Oct 2026 00:00:00 +0000 +Subject: [PATCH] ci/build: vendor our own OpenSSL on riscv64 + +collect_deps resolves the binary's NEEDED entries with a plain ldd, run +before patchelf gives it an RPATH. On manylinux_2_39_riscv64 that finds +Rocky 10's own OpenSSL (3.5.5) on the default loader path and vendors it: + + Vendoring: libssl.so.3 (/lib64/lp64d/libssl.so.3) + Vendoring: libcrypto.so.3 (/lib64/lp64d/libcrypto.so.3) + +manylinux2014 has no libssl.so.3, so on x86_64/aarch64 ldd reports it +"not found" and the "vendor the OpenSSL .so files we built from source" +fallback that follows ships the 3.0.15 HAProxy was compiled and linked +against. On riscv64 that fallback skips both sonames because Rocky 10's +copies are already in lib/. + +Point that ldd walk at the OpenSSL built here, on riscv64 only. Keep it +scoped to the collect_deps call: exported for the rest of the script, +it also reaches binutils, whose readelf links libcurl through +libdebuginfod, and Rocky 10's libcurl needs a newer OpenSSL than 3.0.15 +exports, so every later readelf fails to start: + + readelf: .../lib/libssl.so.3: version `OPENSSL_3.2.0' not found (required by /lib64/lp64d/libcurl.so.4) + +which silently turned the script's hardening checks into "NO". + +Upstream-Status: Inappropriate [manylinux2014 (x86_64/aarch64) has no libssl.so.3 on the default loader path, so upstream's targets already vendor the OpenSSL they build] + +Signed-off-by: Ludovic Henry +--- +diff --git a/ci/build/build-haproxy-dist.sh b/ci/build/build-haproxy-dist.sh +--- a/ci/build/build-haproxy-dist.sh ++++ b/ci/build/build-haproxy-dist.sh +@@ -244,7 +244,17 @@ collect_deps() { + done + } + +-collect_deps "$STAGE_DIR/haproxy" ++if [ "$ARCH_LABEL" = "riscv64" ]; then ++ # manylinux_2_39_riscv64 (Rocky 10) ships its own libssl.so.3/libcrypto.so.3 ++ # on the default loader path, which manylinux2014 doesn't, so a plain ldd ++ # would vendor Rocky's OpenSSL instead of the one built above. Scope this to ++ # the ldd walk: exported script-wide it also reaches binutils, whose ++ # readelf links libcurl (via libdebuginfod) and then fails to start against ++ # this older OpenSSL. ++ LD_LIBRARY_PATH="$OPENSSL_LIB_DIR" collect_deps "$STAGE_DIR/haproxy" ++else ++ collect_deps "$STAGE_DIR/haproxy" ++fi + + # Also vendor the OpenSSL .so files we built from source — ldd sees them by + # their build path, but make sure their sonames are in lib/.