Skip to content

fix(release): portable Linux binaries (glibc 2.17 + static musl) and SDK version drift - #2671

Open
vieiralucas wants to merge 1 commit into
mainfrom
fix-dist-glibc-sdk-versions
Open

vieiralucas wants to merge 1 commit into
mainfrom
fix-dist-glibc-sdk-versions

Conversation

@vieiralucas

@vieiralucas vieiralucas commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Distribution fixes from the 2026-10-01 bug audit (D.1, D.2, D.3).

D.1 Portable Linux binaries. The Linux release binaries were built with a plain cargo build on ubuntu-24.04 (glibc 2.39) and dynamically linked the runner's libssl.so.3 (RDS MySQL client -> mysql_async -> native-tls). They failed to start on Amazon Linux 2, RHEL 8, Debian 11 and Ubuntu 20.04, and install.sh downloaded that glibc build on Alpine, where it cannot run at all.

  • release.yml: linux-amd64 / linux-arm64 now build with cargo-zigbuild against glibc 2.17 (x86_64-unknown-linux-gnu.2.17, aarch64-unknown-linux-gnu.2.17). 2.17 rather than 2.28 because Amazon Linux 2 ships glibc 2.26. New static linux-amd64-musl / linux-arm64-musl assets. zig 0.16.0 (PyPI ziglang) and cargo-zigbuild 0.23.4 are pinned.
  • New vendored-openssl feature on the fakecloud crate (optional direct openssl dep with vendored), so OpenSSL is compiled from source and linked statically. LIBZ_SYS_STATIC / LZMA_API_STATIC do the same for zlib / liblzma. Default builds (cargo install, Docker, Homebrew) are unchanged.
  • A new "Verify Linux binary portability" step fails the build if the binary NEEDs anything beyond glibc's own libs, if a musl build is not fully static, or if any GLIBC_x.y symbol version is above 2.17. It then runs fakecloud --version.
  • Existing asset names are unchanged. The musl builds add a -musl suffix: fakecloud-<tag>-linux-<arch>-musl.tar.gz.
  • install.sh detects musl (ldd --version, then getconf GNU_LIBC_VERSION, /etc/alpine-release, /lib/ld-musl-*.so.1) and picks the -musl asset. --libc musl|gnu or FAKECLOUD_LIBC overrides the detection. If a musl asset is missing because the release predates musl builds, it prints a clear error. website/static/install.sh is a symlink to it, so the hosted script updates too.
  • The install docs describe the libc selection, the Alpine | sh form and the asset names.
  • Unrelated actionlint finding fixed in the same file: the Packagist mirror URL is now quoted (SC2086).

D.2. The Bedrock model id in sdks/java/README.md is back to anthropic.claude-3-haiku-20240307-v1:0. It had been corrupted since v0.40.1 by the release skill's unescaped-dot OLD -> NEW replace (024030 in the date matches the regex 0.40.0). I scanned the diff of every chore(release) commit and this was the only collateral change. The skill (outside the repo) now uses an escaped $OLD_RE, a replace anchored to its context, and a post-bump check that flags any changed line not containing the new version.

D.3. Synced to 0.47.0: sdks/dotnet/README.md (was 0.44.1), sdks/typescript/package-lock.json (was 0.40.1), and the stale website install snippets docs/sdks/dotnet.md (0.44.1), docs/sdks/java.md / docs/sdks/_index.md (0.15.0) and docs/getting-started/sdk-setup.md (0.12.0). All of them are now in the release skill's bump list.

Non-code surfaces: SDK code in all 7 languages is unaffected (version strings only). AGENTS.md is not affected. The binary-size claim (~19 MB) on the install page was already stale before this change: the current v0.47.0 linux tarball is 72.6 MB. The new glibc-2.17 tarball is 69.5 MB, so this PR does not make it worse. I did not touch that claim because it is tracked by check-doc-counts.sh.

Test plan

  • actionlint .github/workflows/release.yml is clean.
  • Local cargo zigbuild --release --locked --target x86_64-unknown-linux-gnu.2.17 --bin fakecloud --features vendored-openssl (macOS host, zig 0.16.0, cargo-zigbuild 0.23.4) passed. ring, aws-lc-sys and vendored openssl-src all built under zig with no extra cmake/nasm setup. Resulting NEEDED libs: libc, libm, libpthread, libdl, ld-linux-x86-64 (no libssl). Highest symbol version is GLIBC_2.17.
  • Local x86_64-unknown-linux-musl zigbuild: MUSL_RESULT
  • Ran install.sh libc detection against stub ldd outputs for musl (Alpine), GNU libc (Amazon Linux 2) and Ubuntu GLIBC. Results: musl, gnu, gnu. sh -n and shellcheck are clean.
  • Dry-ran the new release-skill bump commands on copies of the Java and .NET READMEs. Only the version coordinates changed; the model id is untouched.
  • I could not run the binaries in amazonlinux:2 / alpine containers because the local Docker daemon was unresponsive. The release workflow's verification step covers this on CI.

Summary by cubic

Makes Linux release binaries portable so they run on older glibc distros (Amazon Linux 2, RHEL 8, Debian 11, Ubuntu 20.04) and on Alpine, and fixes stale SDK version references left behind by the release skill.

Release binaries

  • Linux amd64/arm64 now build with cargo-zigbuild against glibc 2.17 instead of the runner's glibc 2.39, and add fully static musl assets (-musl suffix) for Alpine.
  • OpenSSL, zlib, and liblzma are compiled from source and linked statically via a new vendored-openssl feature; default builds (cargo install, Docker, Homebrew) are unchanged.
  • install.sh detects musl automatically, supports --libc musl|gnu or FAKECLOUD_LIBC, and errors clearly when a release predates musl builds.
  • The release workflow now fails the build if a binary needs anything beyond glibc's own libs or references a GLIBC_x.y symbol above 2.17.

SDK versions and docs

  • Restored the Java Bedrock model id (anthropic.claude-3-haiku-20240307-v1:0) corrupted by unescaped-dot version replacements since v0.40.1.
  • Synced stale .NET, TypeScript, and Java install snippets to 0.47.0.
  • Quoted the Packagist mirror URL in the release workflow to satisfy actionlint.

Written for commit 45607d5. Summary will update on new commits.

Review in cubic

…SDK version drift

Linux release binaries were built with a plain cargo build on ubuntu-24.04
(glibc 2.39) and dynamically linked the runner's libssl.so.3, so they failed
to start on Amazon Linux 2, RHEL 8, Debian 11 and Ubuntu 20.04, and
install.sh fetched that glibc build on Alpine.

- release.yml: build linux-amd64/arm64 with cargo-zigbuild against glibc
  2.17, add static linux-amd64-musl/arm64-musl assets, statically link
  OpenSSL (new vendored-openssl feature on the fakecloud crate), zlib and
  liblzma, and verify NEEDED libs + max GLIBC symbol version before upload.
- install.sh: detect musl (ldd --version, getconf, /etc/alpine-release,
  ld-musl loader) and pick the -musl asset; --libc / FAKECLOUD_LIBC override.
- Restore the Java README Bedrock model id corrupted by unescaped-dot
  version replaces since v0.40.1 (anthropic.claude-3-haiku-20240307-v1:0).
- Sync stale SDK install snippets to 0.47.0: dotnet README + docs page,
  typescript package-lock.json, Java docs pages.
- Quote the Packagist mirror URL (actionlint SC2086).

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant