From 863cb9ec2f3fc714729e756fe812a016ef6a26ef Mon Sep 17 00:00:00 2001 From: Ludovic Henry Date: Mon, 21 Sep 2026 12:03:59 +0000 Subject: [PATCH] python-olm: Add version 3.2.16 Add the riscv64 wheel build for python-olm 3.2.16, the cffi bindings for libolm, Matrix's Olm/Megolm cryptographic ratchet. The sdist job mirrors upstream's own make_sdist.sh (the released PyPI sdist is byte-identical in file list), and the wheel job builds that sdist with cibuildwheel on the riscv64 manylinux image. libolm's CMakeLists declares cmake_minimum_required(VERSION 3.4), below CMake 4's floor, so the build carries CMAKE_POLICY_VERSION_MINIMUM=3.5. The wheel carried no licence text at all; a patch adds libolm's Apache-2.0 LICENSE and curve25519-donna's BSD-3-Clause notice. --- .github/workflows/build-python-olm.yml | 171 ++++++++++++++++++ docs/packages/python-olm.yaml | 6 + ...hip-libolm-s-licences-with-the-wheel.patch | 56 ++++++ 3 files changed, 233 insertions(+) create mode 100644 .github/workflows/build-python-olm.yml create mode 100644 docs/packages/python-olm.yaml create mode 100644 patches/python-olm/3.2.16/0001-ship-libolm-s-licences-with-the-wheel.patch diff --git a/.github/workflows/build-python-olm.yml b/.github/workflows/build-python-olm.yml new file mode 100644 index 00000000000..96508878acd --- /dev/null +++ b/.github/workflows/build-python-olm.yml @@ -0,0 +1,171 @@ +# SPDX-FileCopyrightText: 2026 The RISE Project +# SPDX-License-Identifier: MIT +--- +# Based on the `dist:python:sdist`/`dist:python:wheel` jobs of +# https://gitlab.matrix.org/matrix-org/olm/-/blob/3.2.16/python/.gitlab-ci.yml +name: Build python-olm wheels (riscv64) + +on: + workflow_dispatch: + inputs: + version: + description: 'Version glob to (re)build; empty builds every version of docs/packages/python-olm.yaml not released yet' + required: false + default: '' + pull_request: + branches: [main] + paths: + - '.github/workflows/build-python-olm.yml' + - 'docs/packages/python-olm.yaml' + push: + branches: [main] + paths: + - '.github/workflows/build-python-olm.yml' + - 'docs/packages/python-olm.yaml' + +concurrency: + group: ${{ github.workflow }}-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +permissions: + contents: read # to fetch code (actions/checkout) + +env: + MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64 + +jobs: + setup: + uses: $/.github/workflows/_setup.yml + with: + package: python-olm + version: ${{ inputs.version }} + + build_sdist: + needs: [setup] + if: needs.setup.outputs.versions != '[]' + name: Build python-olm ${{ matrix.version }} sdist + runs-on: ubuntu-latest + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + + env: + PYTHON_OLM_VERSION: ${{ matrix.version }} + + steps: + # olm is hosted on gitlab.matrix.org, which actions/checkout cannot reach. + - name: Checkout olm ${{ env.PYTHON_OLM_VERSION }} + run: | + git clone --depth 1 --branch "${{ env.PYTHON_OLM_VERSION }}" \ + https://gitlab.matrix.org/matrix-org/olm.git olm-src + + - name: Checkout python-wheels + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + path: python-wheels + persist-credentials: false + + - name: Patch olm source + working-directory: olm-src + run: | + git apply ../python-wheels/patches/python-olm/${{ env.PYTHON_OLM_VERSION }}/00*.patch + + - name: setup uv + uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1 + with: + python-version: '3.12' + activate-environment: true + enable-cache: false + + # The cffi hook runs olm_build.py, and so libolm's cmake build, even for + # an sdist; libolm asks for cmake 3.4, below the floor of cmake 4. + - name: Build sdist + working-directory: olm-src/python + env: + CMAKE_POLICY_VERSION_MINIMUM: '3.5' + run: | + uv pip install build + ./make_sdist.sh + + - name: Upload sdist artifact + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: python-olm-${{ env.PYTHON_OLM_VERSION }}-sdist + path: olm-src/python/dist/*.tar.gz + if-no-files-found: error + + build_wheels: + needs: [setup, build_sdist] + if: needs.setup.outputs.versions != '[]' + name: Build python-olm ${{ matrix.version }} ${{ matrix.python }}-manylinux_riscv64 + runs-on: ubuntu-24.04-riscv + timeout-minutes: 120 + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + python: ["cp312", "cp313", "cp314", "cp314t"] + + env: + PYTHON_OLM_VERSION: ${{ matrix.version }} + + steps: + # The sdist ships no tests; the suite only exists in the git tree. + - name: Checkout olm ${{ env.PYTHON_OLM_VERSION }} tests + run: | + git clone --depth 1 --branch "${{ env.PYTHON_OLM_VERSION }}" \ + https://gitlab.matrix.org/matrix-org/olm.git olm-src + mv olm-src/python/tests tests + + - name: Fetch sdist artifact + uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 + with: + name: python-olm-${{ env.PYTHON_OLM_VERSION }}-sdist + path: dist + + - id: sdist_dir + run: | + tar zxf dist/*.tar.gz -C dist + echo "path=$(echo dist/python_olm-*/)" >> "$GITHUB_OUTPUT" + + - name: Build wheels + uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0 + with: + package-dir: ${{ steps.sdist_dir.outputs.path }} + output-dir: wheelhouse/ + env: + CIBW_ARCHS: riscv64 + CIBW_BUILD: ${{ matrix.python }}-manylinux_riscv64 + CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }} + # cffi has no riscv64 wheel on PyPI. + CIBW_ENVIRONMENT: >- + PIP_EXTRA_INDEX_URL=https://pypi.riseproject.dev/simple/ + CMAKE_POLICY_VERSION_MINIMUM=3.5 + CIBW_TEST_REQUIRES: pytest pytest-benchmark aspectlib + CIBW_TEST_SOURCES: tests + CIBW_TEST_COMMAND: python -m pytest tests --benchmark-disable + + - name: Store wheels + uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: python-olm-${{ env.PYTHON_OLM_VERSION }}-${{ matrix.python }}-manylinux_riscv64 + path: wheelhouse/*.whl + if-no-files-found: error + + publish: + name: Publish python-olm ${{ matrix.version }} + needs: [setup, build_wheels] + if: needs.setup.outputs.versions != '[]' + strategy: + fail-fast: false + matrix: + version: ${{ fromJSON(needs.setup.outputs.versions) }} + permissions: + contents: write + pull-requests: write + uses: $/.github/workflows/_publish-wheel.yml + secrets: + app-private-key: ${{ secrets.RISEPROJECT_APP_PRIVATE_KEY }} + with: + artifact-pattern: python-olm-${{ matrix.version }}-*-manylinux_riscv64 diff --git a/docs/packages/python-olm.yaml b/docs/packages/python-olm.yaml new file mode 100644 index 00000000000..97bce264fbd --- /dev/null +++ b/docs/packages/python-olm.yaml @@ -0,0 +1,6 @@ +package-name: python-olm +source-code: https://gitlab.matrix.org/matrix-org/olm +license: Apache-2.0 +versions: +- version: 3.2.16 + patched: true diff --git a/patches/python-olm/3.2.16/0001-ship-libolm-s-licences-with-the-wheel.patch b/patches/python-olm/3.2.16/0001-ship-libolm-s-licences-with-the-wheel.patch new file mode 100644 index 00000000000..8dccb9764a3 --- /dev/null +++ b/patches/python-olm/3.2.16/0001-ship-libolm-s-licences-with-the-wheel.patch @@ -0,0 +1,56 @@ +From be65e6ef1e2a0d0e0186947bff0620ada84df7ba Mon Sep 17 00:00:00 2001 +From: Ludovic Henry +Date: Mon, 21 Sep 2026 11:57:35 +0000 +Subject: [PATCH] ship libolm's licences with the wheel + +Upstream-Status: To upstream [libolm is deprecated upstream and its last commit predates this; the same gap exists in every python-olm wheel on PyPI] + +The extension statically links the whole of libolm (Apache-2.0) together with +the bundled curve25519-donna (BSD-3-Clause), whose terms both require their +notice to travel with a binary redistribution. Neither reaches the wheel: +make_sdist.sh never copies the repository's LICENSE into the sdist, so +setuptools' default license-file glob finds nothing and the built wheel ships +no notice at all. + +Copy LICENSE beside the generated headers and name both files explicitly, so +setuptools keeps each entry's path relative to the project root and they land +in the wheel as dist-info/licenses/LICENSE and +dist-info/licenses/libolm/lib/curve25519-donna/LICENSE.md. + +The other vendored sources compiled in, Brad Conte's crypto-algorithms and the +ref10-derived ed25519, are both public domain and ask for no notice. + +Signed-off-by: Ludovic Henry +--- + python/make_sdist.sh | 1 + + python/setup.cfg | 5 +++++ + 2 files changed, 6 insertions(+) + +diff --git a/python/make_sdist.sh b/python/make_sdist.sh +index 7f90fdb..7fbfd68 100755 +--- a/python/make_sdist.sh ++++ b/python/make_sdist.sh +@@ -15,6 +15,7 @@ mkdir -p libolm + echo "Cleaning sources" + make clean > /dev/null + cp -a $SRC/include . ++cp -a $SRC/../LICENSE . + echo "Copying libolm sources" + for src in cmake CMakeLists.txt common.mk include lib Makefile olm.pc.in src tests; do + cp -a $SRC/../$src libolm +diff --git a/python/setup.cfg b/python/setup.cfg +index 1be5f25..a886abc 100644 +--- a/python/setup.cfg ++++ b/python/setup.cfg +@@ -3,3 +3,8 @@ testpaths = tests + flake8-ignore = + olm/*.py F401 + tests/*.py W503 ++ ++[metadata] ++license_files = ++ LICENSE ++ libolm/lib/curve25519-donna/LICENSE.md +-- +2.43.0 +