diff --git a/.github/workflows/build-engines.yml b/.github/workflows/build-engines.yml index 9ebdd1fba..bd8b39bff 100644 --- a/.github/workflows/build-engines.yml +++ b/.github/workflows/build-engines.yml @@ -104,8 +104,8 @@ jobs: fail-fast: false matrix: target: - - { os: ubuntu-24.04, platform: linux-x64 } - - { os: ubuntu-24.04-arm, platform: linux-arm64 } + - { os: ubuntu-24.04, platform: linux-x64, manylinux: quay.io/pypa/manylinux_2_28_x86_64 } + - { os: ubuntu-24.04-arm, platform: linux-arm64, manylinux: quay.io/pypa/manylinux_2_28_aarch64 } - { os: windows-2025, platform: win32-x64 } runs-on: ${{ matrix.target.os }} steps: @@ -119,10 +119,19 @@ jobs: path: engines key: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}-${{ needs.generate.outputs.key }} restore-keys: engines-${{ matrix.target.platform }}-${{ needs.generate.outputs.flags }}- - - name: Compile every language (Linux) + # THE GLIBC FLOOR. A binary links against the glibc of the machine that built it, and runs only where that + # glibc or a newer one is installed. Built on ubuntu-24.04 (glibc 2.39) every engine needed GLIBC_2.38, so it + # would not start on Ubuntu 22.04, Debian 12, RHEL 9 or Amazon Linux 2023: the official python and node + # Docker images, most CI and most servers. The compile therefore runs inside manylinux_2_28 (glibc 2.28, + # the floor Python wheels use), and the step after it fails the build if any binary asks for more. + - name: Compile every language (Linux, manylinux_2_28) if: startsWith(matrix.target.platform, 'linux') + env: + MANYLINUX: ${{ matrix.target.manylinux }} run: | set -e + docker run --rm -v "$PWD:/w" -w /w -e LANGUAGES="$LANGUAGES" -u "$(id -u):$(id -g)" "$MANYLINUX" bash -ec ' + c++ --version | head -1; ldd --version | head -1 for lang in $LANGUAGES; do if cmp -s "gen/$lang.id" "engines/$lang/ENGINE_ID"; then echo "$lang: cached, rules unchanged"; continue; fi mkdir -p "engines/$lang" @@ -136,7 +145,19 @@ jobs: c++ -std=c++17 -O3 -w -static-libstdc++ -static-libgcc -I gen "$cpp" -o "engines/queries/axiomcode-query-$q" cp "gen/queries/$q.id" "engines/queries/$q.id" done + ' ls -la engines/*; ldd engines/java/axiomcode-engine-java || true + - name: Linux binaries need no glibc newer than 2.28 + if: startsWith(matrix.target.platform, 'linux') + run: | + set -e + bad=0 + for f in engines/*/axiomcode-*; do + need="$(objdump -T "$f" | grep -o 'GLIBC_[0-9.]*' | sed 's/GLIBC_//' | sort -V | tail -1)" + echo "$f needs glibc $need" + if [ "$(printf '%s\n2.28\n' "$need" | sort -V | tail -1)" != 2.28 ]; then echo "::error::$f needs glibc $need (> 2.28)"; bad=1; fi + done + exit $bad - uses: ilammy/msvc-dev-cmd@v1 if: startsWith(matrix.target.platform, 'win32') with: { arch: x64 }