From 1b9c2f1555a6b46d8014dbd298abcad997de1b56 Mon Sep 17 00:00:00 2001 From: Ludovic Henry Date: Mon, 7 Sep 2026 22:07:00 +0200 Subject: [PATCH 1/3] pyrage: add build-pyrage.yml for riscv64 wheels Rust/PyO3 bindings for the age file encryption tool. pyo3's abi3-py310 feature is unconditional in Cargo.toml, so a single abi3 wheel covers cp310-cp314 and the free-threaded build gets its own cp314t wheel. No C dependencies (age is pure Rust), so no in-container native toolchain beyond rustup is needed. --- .github/workflows/build-pyrage.yml | 97 ++++++++++++++++++++++++++++++ 1 file changed, 97 insertions(+) create mode 100644 .github/workflows/build-pyrage.yml diff --git a/.github/workflows/build-pyrage.yml b/.github/workflows/build-pyrage.yml new file mode 100644 index 000000000..21dec0818 --- /dev/null +++ b/.github/workflows/build-pyrage.yml @@ -0,0 +1,97 @@ +# SPDX-FileCopyrightText: 2026 The RISE Project +# SPDX-License-Identifier: MIT +--- +# This workflow is based on the `test`/`release-linux` jobs of +# https://github.com/woodruffw/pyrage/blob/v1.4.0/.github/workflows/ci.yml and +# https://github.com/woodruffw/pyrage/blob/v1.4.0/.github/workflows/release.yml +name: Build pyrage wheels (riscv64) + +on: + workflow_dispatch: + inputs: + version: + description: 'pyrage version to build (git tag without the leading v, e.g. 1.4.0)' + required: true + default: '1.4.0' + pull_request: + paths: + - '.github/workflows/build-pyrage.yml' + +concurrency: + group: ${{ github.workflow }}-${{ inputs.version || '1.4.0' }}-${{ github.head_ref || github.run_id }} + cancel-in-progress: true + +permissions: + contents: read # to fetch code (actions/checkout) + +env: + # `inputs.version` is empty on pull_request events; default to 1.4.0 there. + PYRAGE_VERSION: ${{ inputs.version || '1.4.0' }} + MANYLINUX_RISCV64_IMAGE: quay.io/pypa/manylinux_2_39_riscv64 + +jobs: + setup: + uses: $/.github/workflows/_setup.yml + + build_wheels: + needs: [setup] + name: Build pyrage ${{ inputs.version || '1.4.0' }} ${{ matrix.tag }}-manylinux_riscv64 + runs-on: ubuntu-24.04-riscv + timeout-minutes: 60 + strategy: + fail-fast: false + matrix: + include: + # pyo3's abi3-py310 feature is on unconditionally, so one abi3 wheel + # serves every GIL-ful interpreter; pyo3 disables abi3 under + # Py_GIL_DISABLED, giving the free-threaded build its own wheel. + - tag: cp310-abi3 + build: >- + cp310-manylinux_riscv64 cp311-manylinux_riscv64 + cp312-manylinux_riscv64 cp313-manylinux_riscv64 + cp314-manylinux_riscv64 + - tag: cp314t + build: cp314t-manylinux_riscv64 + + steps: + - name: Checkout pyrage v${{ env.PYRAGE_VERSION }} + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + with: + repository: woodruffw/pyrage + ref: v${{ env.PYRAGE_VERSION }} + persist-credentials: false + + - name: Build and test wheel + uses: pypa/cibuildwheel@1828c10ab37f080699c7b81cea34097c684a7074 # v4.2.0 + with: + output-dir: wheelhouse/ + env: + # musllinux is dropped: rustup.rs ships no riscv64 musl toolchain. + CIBW_BUILD: ${{ matrix.build }} + CIBW_MANYLINUX_RISCV64_IMAGE: ${{ env.MANYLINUX_RISCV64_IMAGE }} + # pyrage ships no [tool.cibuildwheel], so the Rust toolchain its + # maturin backend needs is installed in-container here. + CIBW_BEFORE_ALL_LINUX: >- + curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh -s -- -y + CIBW_ENVIRONMENT_LINUX: PATH="$PATH:$HOME/.cargo/bin" + CIBW_TEST_REQUIRES: pytest parameterized + CIBW_TEST_SOURCES: test + CIBW_TEST_COMMAND: >- + python -c "import pyrage as m; assert m.__file__.endswith('.so'), m.__file__" && + python -m pytest -v test + + - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 + with: + name: pyrage-${{ env.PYRAGE_VERSION }}-${{ matrix.tag }}-manylinux_riscv64 + path: wheelhouse/*.whl + if-no-files-found: error + + publish: + name: Publish pyrage ${{ inputs.version || '1.4.0' }} + needs: [setup, build_wheels] + permissions: + contents: write + pull-requests: write + uses: $/.github/workflows/_publish-wheel.yml + with: + artifact-pattern: pyrage-${{ inputs.version || '1.4.0' }}-*-manylinux_riscv64 From 94da775e13c2d3211e87ab232b039f73dc59a896 Mon Sep 17 00:00:00 2001 From: Ludovic Henry Date: Mon, 7 Sep 2026 22:23:59 +0200 Subject: [PATCH 2/3] pyrage: drop cp314t, pyo3 0.24.2 has no Python 3.14 support Verified via CI: v1.4.0's Cargo.lock pins pyo3 0.24.2, whose build script hard-errors on any non-abi3 build against a 3.14 interpreter ("configured Python interpreter version (3.14) is newer than PyO3's maximum supported version (3.13)"). A bump was tried locally: pyo3-file 0.12.0 also needs bumping (its pyo3 req is pinned to "0.24"), and pyo3 0.29.2 then fails to compile pyrage's own src/*.rs (Python::with_gil was renamed to try_attach), which is too invasive to backport here. --- .github/workflows/build-pyrage.yml | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/.github/workflows/build-pyrage.yml b/.github/workflows/build-pyrage.yml index 21dec0818..0f5bdd239 100644 --- a/.github/workflows/build-pyrage.yml +++ b/.github/workflows/build-pyrage.yml @@ -43,15 +43,21 @@ jobs: matrix: include: # pyo3's abi3-py310 feature is on unconditionally, so one abi3 wheel - # serves every GIL-ful interpreter; pyo3 disables abi3 under - # Py_GIL_DISABLED, giving the free-threaded build its own wheel. + # serves every GIL-ful interpreter up to cp314 (abi3 wheels are + # forward-compatible; only the cp310 build actually compiles). + # cp314t is dropped (gotcha 322): v1.4.0's Cargo.lock pins pyo3 + # 0.24.2, whose build script hard-errors "configured Python + # interpreter version (3.14) is newer than PyO3's maximum + # supported version (3.13)" for any non-abi3 (free-threaded) + # build. Bumping pyo3 needs a pyo3-file bump too and then breaks + # on pyo3 0.29's Python::with_gil -> try_attach rename across + # every src/*.rs file - too invasive for this port; upstream + # fixed this on main post-v1.4.0 by bumping to pyo3 0.29.2. - tag: cp310-abi3 build: >- cp310-manylinux_riscv64 cp311-manylinux_riscv64 cp312-manylinux_riscv64 cp313-manylinux_riscv64 cp314-manylinux_riscv64 - - tag: cp314t - build: cp314t-manylinux_riscv64 steps: - name: Checkout pyrage v${{ env.PYRAGE_VERSION }} From 61fa97229bfb7eaec426d6b16ff86f6f1a5e78c4 Mon Sep 17 00:00:00 2001 From: Ludovic Henry Date: Mon, 7 Sep 2026 22:49:46 +0200 Subject: [PATCH 3/3] pyrage: fix .so smoke test, maturin ships an __init__.py shim (gotcha 314) pyrage has no [tool.maturin] python-source, so maturin auto-generates pyrage/__init__.py wrapping the compiled pyrage/pyrage.abi3.so submodule; pyrage.__file__ is the shim, not the extension. --- .github/workflows/build-pyrage.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build-pyrage.yml b/.github/workflows/build-pyrage.yml index 0f5bdd239..e2fa4457b 100644 --- a/.github/workflows/build-pyrage.yml +++ b/.github/workflows/build-pyrage.yml @@ -82,8 +82,11 @@ jobs: CIBW_ENVIRONMENT_LINUX: PATH="$PATH:$HOME/.cargo/bin" CIBW_TEST_REQUIRES: pytest parameterized CIBW_TEST_SOURCES: test + # No python-source in pyproject.toml, so maturin ships an auto-generated + # pyrage/__init__.py shim around the compiled pyrage/pyrage.*.so submodule + # (gotcha 314) - probe that submodule, not the top-level import. CIBW_TEST_COMMAND: >- - python -c "import pyrage as m; assert m.__file__.endswith('.so'), m.__file__" && + python -c "import pyrage.pyrage as m; assert m.__file__.endswith('.so'), m.__file__" && python -m pytest -v test - uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1