From 308803053ca336b6fd768b94e260d33b5380c0ee Mon Sep 17 00:00:00 2001 From: Koda YeenBean Date: Mon, 20 Jul 2026 00:03:28 +0100 Subject: [PATCH] fixing release pipeline (#40) Reviewed-on: https://git.ascheu.de/Koda/OpenUniFi/pulls/40 Co-authored-by: Koda YeenBean --- AGENTS.md | 5 +++++ scripts/ci/build-release.sh | 16 ++++++++++------ 2 files changed, 15 insertions(+), 6 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index 30588da..b64a7de 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -114,6 +114,11 @@ behavior that still needs manual testing. - Ordinary read-only commands may fail with the same `bwrap` namespace error. When the command is safe and required, rerun it using the environment's normal escalation/approval mechanism instead of investigating the namespace setup. +- OpenWrt's release SDK host tools and preload libraries are x86-64. When using + them through QEMU on an ARM runner, never export the SDK's fakeroot library as + host `LD_PRELOAD`; carry it in a private variable and pass it to the bundled + x86 loader with `--preload`. Validate changes with an emulated build through + mbedTLS packaging, where a broken handoff appears as a `library/...` dependency. Agents must preserve useful environment knowledge for later agents. When a new pitfall or workaround is verified to be deterministic or repeatedly encountered, diff --git a/scripts/ci/build-release.sh b/scripts/ci/build-release.sh index 572e5d2..c39e8dd 100755 --- a/scripts/ci/build-release.sh +++ b/scripts/ci/build-release.sh @@ -60,9 +60,16 @@ case $build_host in exit 1 } sed -i -E \ - -e 's|^export LD_PRELOAD=.*(\$dir/.*runas\.so)"$|sdk_preload="\1"|' \ + -e 's|^export LD_PRELOAD=.*(\$dir/.*runas\.so)"$|sdk_preload="${SDK_GUEST_LD_PRELOAD:+$SDK_GUEST_LD_PRELOAD:}\1"\nunset LD_PRELOAD SDK_GUEST_LD_PRELOAD|' \ -e "s|^exec (\"\\\$dir/.*ld-linux-x86-64\\.so\\.2\")|exec ${qemu_x86_64} \\1 --preload \"\\\$sdk_preload\"|" \ "${sdk_wrappers[@]}" + + # fakeroot normally exports its x86-64 preload before invoking a wrapped + # command. Carry it in a private variable so ARM-native env/bash never try + # to load it; the wrapper above passes it directly to the guest loader. + fakeroot_script=staging_dir/host/bin/fakeroot + sed -i 's/LD_PRELOAD="$FAKEROOT_LIB"/SDK_GUEST_LD_PRELOAD="$FAKEROOT_LIB"/g' "$fakeroot_script" + grep -q 'SDK_GUEST_LD_PRELOAD="$FAKEROOT_LIB"' "$fakeroot_script" staging_dir/host/bin/sed --version >/dev/null ;; *) @@ -110,11 +117,8 @@ make defconfig build_jobs=$(nproc) case $build_host in aarch64|arm64|armv7l|armv8l) - # The x86-64 SDK host tools run through QEMU on ARM. In particular, - # concurrent mbedTLS links can leave partially written libraries behind; - # a later serial retry then packages that corrupted output. Build serially - # from a clean SDK extraction instead. - make -j1 package/openuf/compile V=sc + (( build_jobs <= 2 )) || build_jobs=2 + make -j"$build_jobs" package/openuf/compile V=sc ;; *) if ! make -j"$build_jobs" package/openuf/compile; then