-
Notifications
You must be signed in to change notification settings - Fork 0
145 lines (131 loc) · 5.55 KB
/
Copy pathbuild-ddtrace.yml
File metadata and controls
145 lines (131 loc) · 5.55 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
# SPDX-FileCopyrightText: 2026 The RISE Project
# SPDX-License-Identifier: MIT
---
# Based on upstream's wheel builder:
# https://github.com/DataDog/dd-trace-py/blob/v4.13.1/.github/workflows/build_python_3.yml
name: Build ddtrace wheels (riscv64)
on:
workflow_dispatch:
inputs:
version:
description: 'Version glob to (re)build; empty builds every version of docs/packages/ddtrace.yaml not released yet'
required: false
default: ''
pull_request:
branches: [main]
paths:
- '.github/workflows/build-ddtrace.yml'
- 'docs/packages/ddtrace.yaml'
push:
branches: [main]
paths:
- '.github/workflows/build-ddtrace.yml'
- 'docs/packages/ddtrace.yaml'
concurrency:
group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }}
cancel-in-progress: true
permissions:
contents: read # to fetch code (actions/checkout)
env:
MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64
# setup.py's LIBDDWAF_VERSION. Upstream downloads a prebuilt libddwaf, which
# is published for aarch64/x86_64 only, so riscv64 compiles it from source.
LIBDDWAF_VERSION: '2.0.0'
jobs:
setup:
uses: $/.github/workflows/_setup.yml
with:
package: ddtrace
version: ${{ inputs.version }}
build_wheels:
needs: [setup]
if: needs.setup.outputs.versions != '[]'
name: Build ddtrace ${{ matrix.version }} ${{ matrix.python }}-manylinux_riscv64
runs-on: ubuntu-24.04-riscv
timeout-minutes: 720
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
# Upstream skips cp314t and publishes no free-threaded wheel anywhere.
python: ["cp312", "cp313", "cp314"]
env:
DDTRACE_VERSION: ${{ matrix.version }}
steps:
- name: Checkout dd-trace-py v${{ env.DDTRACE_VERSION }}
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: DataDog/dd-trace-py
ref: v${{ env.DDTRACE_VERSION }}
persist-credentials: false
- name: Checkout python-wheels
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
path: python-wheels
persist-credentials: false
- name: Apply riscv64 patches
run: git apply -v python-wheels/patches/ddtrace/${{ env.DDTRACE_VERSION }}/*.patch
- name: Build wheels
uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0
with:
only: ${{ matrix.python }}-manylinux_riscv64
env:
CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }}
CIBW_ENVIRONMENT_LINUX: >-
PATH=$PATH:$HOME/.cargo/bin
PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/
# setup.py drops libddwaf into the wheel from
# ddtrace/appsec/_ddwaf/libddwaf/<arch>/lib/ and skips the download
# when that tree already exists, so building it here is enough.
CIBW_BEFORE_ALL_LINUX: |
set -euxo pipefail
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y
dnf -y install libstdc++-static # libddwaf links -static-libstdc++
git clone --depth 1 --branch "${{ env.LIBDDWAF_VERSION }}" \
https://github.com/DataDog/libddwaf.git /tmp/libddwaf
cmake -S /tmp/libddwaf -B /tmp/libddwaf/build \
-DCMAKE_BUILD_TYPE=RelWithDebInfo \
-DLIBDDWAF_BUILD_STATIC=OFF -DLIBDDWAF_TESTING=OFF
cmake --build /tmp/libddwaf/build --parallel "$(nproc)"
cmake --install /tmp/libddwaf/build --prefix /tmp/libddwaf/install
install -D /tmp/libddwaf/install/lib*/libddwaf.so \
{project}/ddtrace/appsec/_ddwaf/libddwaf/riscv64/lib/libddwaf.so
# setup.py drives CMake through the `cmake` PyPI package, whose oldest
# riscv64 wheel is 4.1.0 — outside pyproject.toml's `cmake<3.28` pin,
# hence the preinstall and pip's unvalidated --no-build-isolation.
CIBW_BEFORE_BUILD: >-
pip install cython "cmake>=4.1" "setuptools-rust<2"
"patchelf>=0.17.0.0" setuptools wheel
CIBW_BUILD_FRONTEND: "pip; args: --no-build-isolation"
CIBW_TEST_COMMAND: python {project}/tests/smoke_test.py
- name: Check the native extensions made it into the wheel
run: |
python3 - wheelhouse/*.whl <<'EOF'
import sys, zipfile
for whl in sys.argv[1:]:
names = [n for n in zipfile.ZipFile(whl).namelist() if n.endswith(".so")]
assert "ddtrace/appsec/_ddwaf/libddwaf/riscv64/lib/libddwaf.so" in names, whl
assert len(names) > 15, (whl, names)
print(whl, len(names), "shared objects")
EOF
- uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: ddtrace-${{ env.DDTRACE_VERSION }}-${{ matrix.python }}-manylinux_riscv64
path: wheelhouse/*.whl
if-no-files-found: error
publish:
name: Publish ddtrace ${{ matrix.version }}
needs: [setup, build_wheels]
if: needs.setup.outputs.versions != '[]'
strategy:
fail-fast: false
matrix:
version: ${{ fromJSON(needs.setup.outputs.versions) }}
permissions:
contents: write
pull-requests: write
uses: $/.github/workflows/_publish-wheel.yml
secrets:
app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }}
with:
artifact-pattern: ddtrace-${{ matrix.version }}-*-manylinux_riscv64