Skip to content

Add pyre-check 0.10.0 - #2661

Merged
luhenry merged 3 commits into
mainfrom
pyre-check
Oct 5, 2026
Merged

luhenry merged 3 commits into
mainfrom
pyre-check

Conversation

@luhenry

@luhenry luhenry commented Oct 3, 2026 •

Copy link
Copy Markdown
Member

The wheel ships pyre.bin, an OCaml binary (OCaml 4.14.2 with flambda, built through opam). Upstream publishes no riscv64 wheel, only a manylinux1_x86_64 one.

Mirrors upstream's pysa.yml and its scripts/pypi packaging.

Differs from upstream

  • Builds in a riscv64/ubuntu:24.04 container - the riscv64 equivalent of upstream's ubuntu-latest with apt opam
  • --release profile - this is what the PyPI binary uses, not the dev build CI tests
  • Pins setuptools<70 and wheel==0.38.4 - the generator named in the released wheels

Testing

  • upstream's deliberately_vulnerable_flask_app Pysa integration test, run against the installed wheel

License: Same as upstream: pyre.bin statically links the OCaml runtime and the opam libraries.

Patches

  • 0001-scripts-pypi-package-the-client-as-Pysa.patch - Backport [facebook/Pysa@f3057a5]. Without it the client ships as pyre_check, but the released 0.10.0 wheels ship it as Pysa.
  • 0002-Build-and-package-pyre.bin-on-riscv64.patch - To upstream. On rv64gc, pause does not assemble, the fixed 80 TiB shm address is out of range under Sv39, and the packaging script rejects the riscv64 ld.so. riscv64-only.

Build pyre.bin (OCaml 4.14.2 + flambda via opam, as upstream's pysa
workflow does) in a riscv64/ubuntu:24.04 container, package it with
upstream's scripts/pypi, and run upstream's deliberately_vulnerable_flask_app
Pysa integration test against the installed wheel.
luhenry added a commit that referenced this pull request Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1

QR code for preview link

🚀 View preview at
https://riseproject-dev.github.io/python-wheels/pr-preview/pr-2661/

Built to branch gh-pages at 2026-10-04 01:36 UTC.
Preview will be ready when the GitHub Pages deployment is complete.

build_pypi_package.py builds the wheel under tempfile.mkdtemp(),
which defaults to /tmp, then os.replace()s it into --output-dir
(../dist, resolving to /workspace/dist). Inside the riscv64/ubuntu:24.04
container, /tmp is the container's own overlay/tmpfs, a different
device from /workspace (bind-mounted from the runner host via
`podman run -v`), so os.replace() (rename(2)) fails with
"OSError: [Errno 18] Invalid cross-device link".

Point TMPDIR at /workspace/tmp, on the same bind-mounted filesystem as
../dist, so the wheel's final move stays on one device. Set inside
riscv64-build.sh so it applies to the container's own python process,
not just the GitHub Actions runner host.
luhenry added a commit that referenced this pull request Oct 3, 2026
PR #2661's first CI run failed moving the built wheel into dist/ with
"Invalid cross-device link": pyre-check's build_pypi_package.py builds
in /tmp (tempfile.mkdtemp) and os.replace()s into ../dist, but inside
the riscv64/ubuntu:24.04 podman container /tmp and the bind-mounted
/workspace are different devices. Fixed on the pyre-check branch by
pointing TMPDIR at /workspace/tmp inside the container.
…mparison

The integration test died with `pyrefly.pysa.json: No such file or
directory`. Pyrefly walked the whole checkout (auto-config rooted at
/workspace/pyproject.toml), hit source/pyrefly.exe, a symlink setup.py
made in the build container to /tmp/buildenv/bin/pyrefly that dangles in
the test container, and aborted with exit 1. The Pysa client reads exit 1
as "type errors found" and ran pyre.bin on a report that was never
written. Not riscv64-specific and not caused by the TMPDIR change.

Fixing the walk would not make the test pass: v0.10.0 removed the Pyre1
backend (--use-pyre1 raises), so the runner always compares against
result.pyrefly.json, which upstream never added (only Pyre1 result.json).
Upstream's own pysa workflow badge is failing on main.

Scope Pyrefly to the app with an empty pyrefly.toml, run the same
`pyre analyze --use-pyrefly --no-verify` the runner runs, and require
taint issues in app.py, printing the overlap with the Pyre1 expectations.
@luhenry
luhenry marked this pull request as ready for review October 4, 2026 05:38
@luhenry
luhenry merged commit abdc2ea into main Oct 5, 2026
9 checks passed
@luhenry
luhenry deleted the pyre-check branch October 5, 2026 08:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant