Skip to content

fix(release): build the Linux x64 Node addon against glibc 2.17 (#1670) - #1678

Merged
DecisionNerd merged 1 commit into
mainfrom
fix/1670-node-x64-glibc-floor
Sep 30, 2026
Merged

DecisionNerd merged 1 commit into
mainfrom
fix/1670-node-x64-glibc-floor

Conversation

@DecisionNerd

@DecisionNerd DecisionNerd commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Closes #1670.

What

.github/workflows/binding-release-candidate.yml:

  • The Linux x64 Node lane now builds with --use-napi-cross, the prebuilt gcc toolchain that links against glibc 2.17, as the aarch64 lane already does. That toolchain's unpacker (@napi-rs/lzma) needs Node ≥ 22, so the lane builds on node_version: "22". It then switches back with a second actions/setup-node step to runtime_node_version: "20", the engines.node floor, and checks the major version before the native smoke and parity contract runs. The executing lane therefore still proves Node 20.
  • New fail-closed step, "Require the declared glibc floor", for every lane with a glibc_floor, which covers both *-unknown-linux-gnu lanes. It reads the addon's highest GLIBC_ version with readelf --dyn-syms --wide, which works on any ELF architecture and so also checks the cross-built aarch64 addon on the x64 host. It refuses anything above 2.17, and runs before the addon is executed.

scripts/ci/test-binding-release-candidate.py: the assertion "only the ARM lane pins a Node version" described the old layout, not a requirement. It now checks the property itself:

  • every --use-napi-cross lane pins a Node ≥ 22 build host;
  • every lane that executes its addon, and pins a build Node, runs the addon on Node 20;
  • runtime_node_version appears only on native lanes that pin a build Node;
  • every Linux glibc lane declares glibc_floor: "2.17", and no other lane declares one;
  • the floor step exists, uses readelf, runs under set -euo pipefail, contains no ||, exits 1 on violation, and comes before the native contract.

Evidence

  • Local build of this exact command (pnpm --filter @curatelabs/graphforge exec napi build --platform --release --target x86_64-unknown-linux-gnu --use-napi-cross, Node 22.22.1, napi CLI 3.10.4):
    • the addon's highest glibc symbol is GLIBC_2.16, and version() returns 0.5.2;
    • test:smoke passed 8/8, and non-cypher-release-parity + async-errors + export-surface passed 9/9.
  • The floor step script, extracted verbatim from the workflow:
    • on that addon, glibc_required=2.16 floor=2.17, exit 0;
    • on the current Bazel-era RC addon (run 36658527263, graphforge.linux-x64-gnu.node), "needs glibc 2.39, above the declared floor 2.17", exit 1.
  • Mutations of the workflow each fail test-binding-release-candidate.py:
    • drop the x64 runtime_node_version;
    • drop the x64 glibc_floor;
    • drop the x64 Node 22 build pin;
    • prefix the readelf line with true ||;
    • remove set -euo pipefail from the floor step.
  • Other checks: python3 scripts/ci/test-binding-release-candidate.py, test-ci-storage-policy.py, workflow_policy.py, scripts/check-workflows.sh (actionlint) and make pre-push-fast all pass. ruff format and ruff check are clean.

Only provable after merge

Binding RC only runs on the current main SHA, so acceptance criterion 1 needs a dispatch on the merge commit: a Binding RC run whose Linux x64 addon is ≤ 2.17 and passes the lane's native contract on Node 20. I'll dispatch it after merge and post the result on #1670.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

The x64 addon was built natively on the Ubuntu 24.04 runner and required
glibc 2.39. Build it with the napi cross toolchain (glibc 2.17) like the
aarch64 addon, on a Node 22 build host, then execute it on the Node 20
engines floor. A fail-closed step reads the highest GLIBC_ version from
each Linux addon and refuses anything above the declared 2.17 floor.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: CurateLabs/graphforge/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 669016c2-a1e2-4d0e-b4d3-7720a595eaa9

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Warning

Billing warning: we have not been able to collect payment for this subscription for more than 72 hours. Please update the payment method or pay any pending invoices in Billing to avoid service interruption.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added core Core source code changes documentation Improvements or additions to documentation ci-cd CI/CD configuration changes tooling Developer tooling and automation labels Sep 30, 2026
@DecisionNerd
DecisionNerd added this pull request to the merge queue Sep 30, 2026
Merged via the queue into main with commit 97fe6d8 Sep 30, 2026
24 checks passed
@DecisionNerd
DecisionNerd deleted the fix/1670-node-x64-glibc-floor branch September 30, 2026 13:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-cd CI/CD configuration changes core Core source code changes documentation Improvements or additions to documentation tooling Developer tooling and automation

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(release): build the Linux x64 Node addon against glibc 2.17

1 participant