fix(release): portable Linux binaries (glibc 2.17 + static musl) and SDK version drift - #2671
Open
vieiralucas wants to merge 1 commit into
Open
vieiralucas wants to merge 1 commit into
vieiralucas wants to merge 1 commit into
Conversation
…SDK version drift Linux release binaries were built with a plain cargo build on ubuntu-24.04 (glibc 2.39) and dynamically linked the runner's libssl.so.3, so they failed to start on Amazon Linux 2, RHEL 8, Debian 11 and Ubuntu 20.04, and install.sh fetched that glibc build on Alpine. - release.yml: build linux-amd64/arm64 with cargo-zigbuild against glibc 2.17, add static linux-amd64-musl/arm64-musl assets, statically link OpenSSL (new vendored-openssl feature on the fakecloud crate), zlib and liblzma, and verify NEEDED libs + max GLIBC symbol version before upload. - install.sh: detect musl (ldd --version, getconf, /etc/alpine-release, ld-musl loader) and pick the -musl asset; --libc / FAKECLOUD_LIBC override. - Restore the Java README Bedrock model id corrupted by unescaped-dot version replaces since v0.40.1 (anthropic.claude-3-haiku-20240307-v1:0). - Sync stale SDK install snippets to 0.47.0: dotnet README + docs page, typescript package-lock.json, Java docs pages. - Quote the Packagist mirror URL (actionlint SC2086).
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Distribution fixes from the 2026-10-01 bug audit (D.1, D.2, D.3).
D.1 Portable Linux binaries. The Linux release binaries were built with a plain
cargo buildon ubuntu-24.04 (glibc 2.39) and dynamically linked the runner'slibssl.so.3(RDS MySQL client ->mysql_async->native-tls). They failed to start on Amazon Linux 2, RHEL 8, Debian 11 and Ubuntu 20.04, andinstall.shdownloaded that glibc build on Alpine, where it cannot run at all.release.yml:linux-amd64/linux-arm64now build withcargo-zigbuildagainst glibc 2.17 (x86_64-unknown-linux-gnu.2.17,aarch64-unknown-linux-gnu.2.17). 2.17 rather than 2.28 because Amazon Linux 2 ships glibc 2.26. New staticlinux-amd64-musl/linux-arm64-muslassets. zig 0.16.0 (PyPIziglang) and cargo-zigbuild 0.23.4 are pinned.vendored-opensslfeature on thefakecloudcrate (optional directopenssldep withvendored), so OpenSSL is compiled from source and linked statically.LIBZ_SYS_STATIC/LZMA_API_STATICdo the same for zlib / liblzma. Default builds (cargo install, Docker, Homebrew) are unchanged.GLIBC_x.ysymbol version is above 2.17. It then runsfakecloud --version.-muslsuffix:fakecloud-<tag>-linux-<arch>-musl.tar.gz.install.shdetects musl (ldd --version, thengetconf GNU_LIBC_VERSION,/etc/alpine-release,/lib/ld-musl-*.so.1) and picks the-muslasset.--libc musl|gnuorFAKECLOUD_LIBCoverrides the detection. If a musl asset is missing because the release predates musl builds, it prints a clear error.website/static/install.shis a symlink to it, so the hosted script updates too.| shform and the asset names.D.2. The Bedrock model id in
sdks/java/README.mdis back toanthropic.claude-3-haiku-20240307-v1:0. It had been corrupted since v0.40.1 by the release skill's unescaped-dotOLD -> NEWreplace (024030in the date matches the regex0.40.0). I scanned the diff of everychore(release)commit and this was the only collateral change. The skill (outside the repo) now uses an escaped$OLD_RE, a replace anchored to its context, and a post-bump check that flags any changed line not containing the new version.D.3. Synced to 0.47.0:
sdks/dotnet/README.md(was 0.44.1),sdks/typescript/package-lock.json(was 0.40.1), and the stale website install snippetsdocs/sdks/dotnet.md(0.44.1),docs/sdks/java.md/docs/sdks/_index.md(0.15.0) anddocs/getting-started/sdk-setup.md(0.12.0). All of them are now in the release skill's bump list.Non-code surfaces: SDK code in all 7 languages is unaffected (version strings only). AGENTS.md is not affected. The binary-size claim (~19 MB) on the install page was already stale before this change: the current v0.47.0 linux tarball is 72.6 MB. The new glibc-2.17 tarball is 69.5 MB, so this PR does not make it worse. I did not touch that claim because it is tracked by
check-doc-counts.sh.Test plan
actionlint .github/workflows/release.ymlis clean.cargo zigbuild --release --locked --target x86_64-unknown-linux-gnu.2.17 --bin fakecloud --features vendored-openssl(macOS host, zig 0.16.0, cargo-zigbuild 0.23.4) passed. ring, aws-lc-sys and vendored openssl-src all built under zig with no extra cmake/nasm setup. Resulting NEEDED libs: libc, libm, libpthread, libdl, ld-linux-x86-64 (no libssl). Highest symbol version isGLIBC_2.17.x86_64-unknown-linux-muslzigbuild: MUSL_RESULTinstall.shlibc detection against stublddoutputs for musl (Alpine), GNU libc (Amazon Linux 2) and Ubuntu GLIBC. Results: musl, gnu, gnu.sh -nand shellcheck are clean.Summary by cubic
Makes Linux release binaries portable so they run on older glibc distros (Amazon Linux 2, RHEL 8, Debian 11, Ubuntu 20.04) and on Alpine, and fixes stale SDK version references left behind by the release skill.
Release binaries
cargo-zigbuildagainst glibc 2.17 instead of the runner's glibc 2.39, and add fully static musl assets (-muslsuffix) for Alpine.vendored-opensslfeature; default builds (cargo install, Docker, Homebrew) are unchanged.install.shdetects musl automatically, supports--libc musl|gnuorFAKECLOUD_LIBC, and errors clearly when a release predates musl builds.GLIBC_x.ysymbol above 2.17.SDK versions and docs
anthropic.claude-3-haiku-20240307-v1:0) corrupted by unescaped-dot version replacements since v0.40.1.Written for commit 45607d5. Summary will update on new commits.