Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
136 changes: 10 additions & 126 deletions .github/workflows/clp-artifact-build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -42,12 +42,6 @@ jobs:
}}
outputs:
# Container-image outputs
centos_stream_9_image_changed: "${{steps.filter.outputs.centos_stream_9_image}}"
centos_stream_9_publish_image: >-
${{steps.calc_workflow_triggers.outputs.is_push_or_run_on_main}}
centos_stream_9_use_published_image: >-
${{steps.filter.outputs.centos_stream_9_image == 'false'
|| steps.calc_workflow_triggers.outputs.is_push_or_run_on_main == 'true'}}
manylinux_2_28_image_changed: "${{steps.filter.outputs.manylinux_2_28_image}}"
manylinux_2_28_publish_image: >-
${{steps.calc_workflow_triggers.outputs.is_push_or_run_on_main}}
Expand Down Expand Up @@ -110,10 +104,6 @@ jobs:
- "components/core/tools/scripts/corporate-proxy-host.sh"
- "components/core/tools/scripts/lib_install/*.sh"
- "components/core/tools/scripts/lib_install/pipx-packages/**"
centos_stream_9_image:
- *_deps_images_common_paths
- "components/core/tools/docker-images/clp-env-base-centos-stream-9/**"
- "components/core/tools/scripts/lib_install/centos-stream-9/**"
manylinux_2_28_image:
- *_deps_images_common_paths
- "components/core/tools/docker-images/clp-env-base-manylinux_2_28/**"
Expand Down Expand Up @@ -151,31 +141,6 @@ jobs:
- ".gitmodules"
- "integration-tests/**"

centos-stream-9-deps-image:
name: "centos-stream-9-deps-image"
if: "needs.calc-build-triggers.outputs.centos_stream_9_image_changed == 'true'"
needs: "calc-build-triggers"
runs-on: *runner
steps:
- uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6.0.2
with:
submodules: "recursive"

- name: "Work around actions/runner-images/issues/6775"
run: "chown $(id -u):$(id -g) -R ."
shell: "bash"

- uses: "./.github/actions/clp-core-build-containers"
env:
OS_NAME: "centos-stream-9"
with:
image_name: "${{env.DEPS_IMAGE_NAME_PREFIX_X86}}${{env.OS_NAME}}"
docker_context: "components/core"
docker_file: "components/core/tools/docker-images/clp-env-base-${{env.OS_NAME}}\
/Dockerfile"
push_deps_image: "${{needs.calc-build-triggers.outputs.centos_stream_9_publish_image}}"
token: "${{secrets.GITHUB_TOKEN}}"

manylinux_2_28-deps-image:
name: "manylinux_2_28-${{matrix.arch}}-deps-image"
if: "needs.calc-build-triggers.outputs.manylinux_2_28_image_changed == 'true'"
Expand Down Expand Up @@ -362,95 +327,6 @@ jobs:
push_deps_image: "${{needs.calc-build-triggers.outputs.ubuntu_jammy_publish_image}}"
token: "${{secrets.GITHUB_TOKEN}}"

centos-stream-9-binaries:
# Run if the ancestor jobs succeeded OR they were skipped and clp was changed.
if: >-
success()
|| (!cancelled() && !failure() && needs.calc-build-triggers.outputs.clp_changed == 'true')
needs:
- "calc-build-triggers"
- "centos-stream-9-deps-image"
strategy:
matrix:
use_shared_libs: [true, false]
name: "centos-stream-9-${{matrix.use_shared_libs == true && 'dynamic' || 'static'}}-linked-bins"
continue-on-error: true
runs-on: *runner
steps:
- uses: "actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd" # v6.0.2
with:
submodules: "recursive"

- name: "Work around actions/runner-images/issues/6775"
run: "chown $(id -u):$(id -g) -R ."
shell: "bash"

- id: "deps_image"
uses: "./.github/actions/prepare-image"
env:
OS_NAME: "centos-stream-9"
with:
image_name: "${{env.DEPS_IMAGE_NAME_PREFIX_X86}}${{env.OS_NAME}}"
use_published_image: >-
${{needs.calc-build-triggers.outputs.centos_stream_9_use_published_image}}

- id: "deps_cache_key"
uses: "./.github/actions/deps-cache-key"
with:
os_name: "centos-stream-9"
env_hash: "${{steps.deps_image.outputs.image_id}}"

# NOTE: Restoring after the `chown` above avoids chowning the restored tree (~2.3GB).
- name: "Restore deps:core cache"
id: "deps_cache_restore"
uses: "actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9" # v6.1.0
with:
# `.task` must travel with the tree, or `clean-outdated-cpp-checksum-files` wipes the
# restored checksums. A `!` exclusion can't prune anything here (`implicitDescendants:
# false`), so large paths are deleted before the save instead.
path: &deps_cache_paths |-
build/deps/cpp
.task
key: "${{steps.deps_cache_key.outputs.key}}"

- uses: "./.github/actions/run-on-image"
env:
OS_NAME: "centos-stream-9"
with:
image_name: "${{env.DEPS_IMAGE_NAME_PREFIX_X86}}${{env.OS_NAME}}"
use_published_image: >-
${{needs.calc-build-triggers.outputs.centos_stream_9_use_published_image}}
prepared_image_id: "${{steps.deps_image.outputs.image_id}}"
run_command: >-
CLP_CPP_MAX_PARALLELISM_PER_BUILD_TASK=$(getconf _NPROCESSORS_ONLN) task deps:core
&& touch /mnt/repo/build/.deps-core-ok
&& python3 /mnt/repo/components/core/tools/scripts/utils/build-and-run-unit-tests.py
${{matrix.use_shared_libs == true && '--use-shared-libs' || ''}}
--source-dir /mnt/repo/components/core
--build-dir /mnt/repo/components/core/build
--num-jobs $(getconf _NPROCESSORS_ONLN)

# `mongocxx` clones `mongo-c-driver` to build it. It needs the checked-out source, but not
# the `.git` directory the clone brings with it -- dropping that before the save takes
# ~200MB off the cache entry.
- name: "Drop mongo-c-driver's .git directory before caching"
if: &deps_cache_save_condition >-
!cancelled()
&& false == matrix.use_shared_libs
&& '' != hashFiles('build/.deps-core-ok')
&& 'true' != steps.deps_cache_restore.outputs.cache-hit
&& 'pull_request' != github.event_name
&& 'refs/heads/main' == github.ref
run: "rm -rf build/deps/cpp/mongocxx-build/_deps/mongo-c-driver-src/.git"
shell: "bash"

- name: "Update deps:core cache"
if: *deps_cache_save_condition
uses: "actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9" # v6.1.0
with:
path: *deps_cache_paths
key: "${{steps.deps_cache_key.outputs.key}}"

manylinux_2_28-x86_64-binaries:
# Run if the ancestor jobs succeeded OR they were skipped and clp was changed.
if: >-
Expand Down Expand Up @@ -499,7 +375,9 @@ jobs:
id: "deps_cache_restore"
uses: "actions/cache/restore@55cc8345863c7cc4c66a329aec7e433d2d1c52a9" # v6.1.0
with:
path: *deps_cache_paths
path: &deps_cache_paths |-
build/deps/cpp
.task
key: "${{steps.deps_cache_key.outputs.key}}"

- uses: "./.github/actions/run-on-image"
Expand All @@ -521,7 +399,13 @@ jobs:
--num-jobs $(getconf _NPROCESSORS_ONLN)

- name: "Drop mongo-c-driver's .git directory before caching"
if: *deps_cache_save_condition
if: &deps_cache_save_condition >-
!cancelled()
&& false == matrix.use_shared_libs
&& '' != hashFiles('build/.deps-core-ok')
&& 'true' != steps.deps_cache_restore.outputs.cache-hit
&& 'pull_request' != github.event_name
&& 'refs/heads/main' == github.ref
run: "rm -rf build/deps/cpp/mongocxx-build/_deps/mongo-c-driver-src/.git"
shell: "bash"

Expand Down
10 changes: 0 additions & 10 deletions components/core/CMakeLists.txt
Original file line number Diff line number Diff line change
Expand Up @@ -84,16 +84,6 @@ set(CLP_USE_STATIC_LIBS ON CACHE BOOL "Whether to link against static libraries"
if (CLP_USE_STATIC_LIBS)
if (APPLE)
set(CLP_STATIC_LIBS_UNSUPPORTED_PLATFORM "macOS")
elseif (EXISTS "/etc/centos-release")
# NOTE:
# 1. We don't support static linking on any CentOS-based distro except manylinux_2_28 (which
# shows up as "AlmaLinux").
# 2. A release called "AlmaLinux" doesn't guarantee we're running on a manylinux distro, but
# we can improve this check when someone reports an issue.
file(READ "/etc/centos-release" CENTOS_RELEASE_CONTENT)
if(NOT "${CENTOS_RELEASE_CONTENT}" MATCHES "AlmaLinux")
set(CLP_STATIC_LIBS_UNSUPPORTED_PLATFORM "CentOS")
endif()
endif()

if (DEFINED CLP_STATIC_LIBS_UNSUPPORTED_PLATFORM)
Expand Down
4 changes: 0 additions & 4 deletions components/core/src/clp/CurlDownloadHandler.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -132,7 +132,6 @@ auto CurlDownloadHandler::get_host_ca_bundle_path() -> std::optional<std::string
}

static constexpr std::string_view cDebianCaBundlePath{"/etc/ssl/certs/ca-certificates.crt"};
static constexpr std::string_view cCentOsCaBundlePath{"/etc/pki/tls/certs/ca-bundle.crt"};

// Read-only operation. No multithreaded context.
// NOLINTNEXTLINE(concurrency-mt-unsafe)
Expand All @@ -147,9 +146,6 @@ auto CurlDownloadHandler::get_host_ca_bundle_path() -> std::optional<std::string
if (std::filesystem::exists(cDebianCaBundlePath)) {
return std::string{cDebianCaBundlePath};
}
if (std::filesystem::exists(cCentOsCaBundlePath)) {
return std::string{cCentOsCaBundlePath};
}
return std::nullopt;
}
} // namespace clp
1 change: 0 additions & 1 deletion components/core/src/clp/CurlDownloadHandler.hpp
Original file line number Diff line number Diff line change
Expand Up @@ -105,7 +105,6 @@ class CurlDownloadHandler {
* variable is set and points to an existing, readable file, that path is returned.
* 2. Known distribution-specific default bundle locations (checked in order):
* - Debian / Ubuntu: `/etc/ssl/certs/ca-certificates.crt`
* - CentOS / RHEL / Fedora: `/etc/pki/tls/certs/ca-bundle.crt`
*
* @return Absolute path to the discovered CA bundle file.
* @return std::nullopt if no CA bundle file could be located. The caller should handle this
Expand Down

This file was deleted.

This file was deleted.

4 changes: 2 additions & 2 deletions components/core/tools/scripts/corporate-proxy-container.sh
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@
# is an error — it means the build was invoked without proper CA setup.
#
# Supports:
# - DNF-based (manylinux_2_28, centos-stream-9)
# - DNF-based (manylinux_2_28)
# - APK/APT-based (musllinux_1_2, ubuntu-jammy)
#
# CA bundle path used by tools (via env vars in the Dockerfile):
Expand Down Expand Up @@ -60,7 +60,7 @@ echo "corporate-proxy-container: installing CA certificates..."
cp "$ca_cert" "${corp_ca_bundle}"

if [[ -d /etc/pki/tls/certs ]]; then
# RHEL/CentOS/manylinux: also copy to the system bundle for tools that
# RHEL/manylinux: also copy to the system bundle for tools that
# don't use env vars.
cp "$ca_cert" "/etc/pki/tls/certs/ca-bundle.crt"
echo "corporate-proxy-container: installed CA bundle (RHEL/manylinux)."
Expand Down
4 changes: 2 additions & 2 deletions components/core/tools/scripts/corporate-proxy-host.sh
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ detect_ca_bundle() {
local ca_paths=(
"${SSL_CERT_FILE:-}" # User/corporate override
/etc/ssl/certs/ca-certificates.crt # Debian/Ubuntu/Alpine
/etc/pki/tls/certs/ca-bundle.crt # RHEL/CentOS/Fedora
/etc/pki/tls/certs/ca-bundle.crt # RHEL/Fedora
/etc/ssl/cert.pem # macOS
)

Expand Down Expand Up @@ -61,7 +61,7 @@ prepare_ca_cert_for_build() {
echo >&2 "ERROR: No CA certificate bundle found on host."
echo >&2 " Expected one of:"
echo >&2 " /etc/ssl/certs/ca-certificates.crt (Debian/Ubuntu/Alpine)"
echo >&2 " /etc/pki/tls/certs/ca-bundle.crt (RHEL/CentOS)"
echo >&2 " /etc/pki/tls/certs/ca-bundle.crt (RHEL)"
echo >&2 " /etc/ssl/cert.pem (macOS)"
exit 1
fi
Expand Down

This file was deleted.

This file was deleted.

Loading
Loading