Add s390x wheels to the build and verification matrix - #2360
Conversation
|
🎉 All Contributor License Agreements have been signed. Ready to merge. |
There was a problem hiding this comment.
🟢 Approval recommended
All reviewed changes are additive and have no unresolved blocking issues.
Pull request overview
Adds native Linux s390x wheel building, verification, and release support.
Changes:
- Selects the correct s390x librdkafka runtime.
- Configures manylinux 2.28 s390x builds.
- Adds Semaphore build and verification lanes.
File summaries
| File | Description |
|---|---|
tools/wheels/install-librdkafka.sh |
Handles s390x runtime library selection. |
tools/wheels/build-wheels.sh |
Configures the s390x manylinux image. |
.semaphore/semaphore.yml |
Adds s390x build and verification blocks. |
Review details
- Files reviewed: 3/3 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
# Conflicts: # .semaphore/semaphore.yml
Since the free-threading work, build-wheels.sh builds a cp314t wheel on every arch, s390x included, but verify-free-threaded-job.sh only handled x64 and arm64, so the s390x cp314t wheel would have been published without verification. - tools/verify-free-threaded-job.sh: add a linux-s390x case. On s390x, install requirements-tests-install-nogil-s390x.txt and skip tests/schema_registry: the schema-registry stack pulls cryptography (via authlib and trivup's jwcrypto), which publishes no s390x wheels. Same scoping as the s390x smoke test. - requirements/requirements-tests-install-nogil-s390x.txt: the nogil test set minus schemaregistry and trivup. - .semaphore/semaphore.yml: add the "Verify free threaded" job to the Linux s390x Wheel Verification block, mirroring arm64.
The container stage of the wheel verification (tools/test-manylinux.sh) runs the smoke test on bare ubuntu images. On s390x several test and extra dependencies publish no s390x wheels and are built from source: fastavro, psutil, librt (via mypy) and cryptography (via the schema-registry deps of the [avro]/[protobuf]/[json] extras). The bare images have no compiler or headers, so the s390x verification failed there. x64 and arm64 are unaffected: these all have wheels there. - On s390x, install gcc, python3.9-dev, libssl-dev and pkg-config in the container before the smoke test. - On s390x, test on ubuntu:22.04 and 24.04 instead of 20.04: cryptography needs OpenSSL >= 3.0 to build and ubuntu:20.04 ships 1.1.1. - Correct the comments in smoketest.sh and requirements-tests-install-s390x.txt: the extras do pull the schema-registry deps, so cryptography is still built from source.
|
Devarsh Patel (@Devarsh010) Free threading related changes look fine. Just a couple of nits. |
| # s390x: the schema-registry stack's deps (cryptography, via authlib) publish | ||
| # no s390x wheels, so the s390x test installs leave them out (see | ||
| # requirements/requirements-tests-install-s390x.txt). Everything under | ||
| # tests/schema_registry needs them: its conftest.py imports the | ||
| # schema-registry client, and with it authlib, at import time. So skip | ||
| # collecting that directory on s390x. The exclusion lives here because that | ||
| # conftest.py would fail to import before it could exclude anything itself. |
There was a problem hiding this comment.
nit: can we please shorten this?
| # s390x: the schema-registry stack's deps (cryptography, via authlib and trivup's | ||
| # jwcrypto) publish no s390x wheels, so install the reduced set (see | ||
| # requirements/requirements-tests-install-nogil-s390x.txt). tests/conftest.py | ||
| # skips collecting tests/schema_registry on s390x to match. |
There was a problem hiding this comment.
nit: You can shorten it to
# s390x: cryptography (via authlib, trivup's jwcrypto) ships no s390x wheels,
# so this installs the reduced requirements-tests-install-nogil-s390x.txt;
# tests/conftest.py skips tests/schema_registry there to match.
|
Build is failing. Also, please run the wheel generation as well as part of this PR. |
| # smoke test installs) publish no s390x wheels and are built from source, | ||
| # which needs a C compiler plus the Python and OpenSSL headers. | ||
| if [[ $(uname -m) == s390x ]]; then | ||
| apt-get install -y -q gcc python3.9-dev libssl-dev pkg-config |
| if platform.machine() == "s390x": | ||
| collect_ignore = ["schema_registry"] |
| commands: | ||
| - export ARCH=s390x | ||
| # sem-version only provides a pip to bootstrap uv; the wheel runs in the 3.14t venv uv creates. | ||
| - sem-version python 3.9 |
There was a problem hiding this comment.
Can we increase this?
| tests_install_reqs="requirements/requirements-tests-install.txt" | ||
| if [[ "$(uname -m)" == "s390x" ]]; then | ||
| tests_install_reqs="requirements/requirements-tests-install-s390x.txt" | ||
| fi |
There was a problem hiding this comment.
use if else for readability
| # mypy, and cryptography via the schema-registry deps of the extras the | ||
| # smoke test installs) publish no s390x wheels and are built from source, | ||
| # which needs a C compiler plus the Python and OpenSSL headers. | ||
| if [[ $(uname -m) == s390x ]]; then |
There was a problem hiding this comment.
| if [[ $(uname -m) == s390x ]]; then | |
| if [[ $(uname -m) == "s390x" ]]; then |
| # no s390x wheel, so it is built against the system OpenSSL, and it needs | ||
| # OpenSSL >= 3.0 (ubuntu:20.04 ships 1.1.1). | ||
| if [[ -z $DOCKER_IMAGES && $(uname -m) == s390x ]]; then | ||
| DOCKER_IMAGES="ubuntu:22.04 ubuntu:24.04" |
There was a problem hiding this comment.
Use this everywhere. We don't need to run on ubuntu 20 anymore. Try adding ubuntu 26 as well.
|
Pranav Rathi (pranavrth)
left a comment
There was a problem hiding this comment.
We need to decrease the build time. Take it as a separate item.
LGTM! Thanks Devarsh Patel (@Devarsh010) !.







What
Adds
linux-s390x(IBM Z) to the Python wheel build and verification matrix, atparity with the existing Linux arm64/x64 lanes, so
pip install confluent-kafkaworks on s390x with a prebuilt manylinux wheel.
tools/wheels/install-librdkafka.sh: on s390x, use the plainlibrdkafka.so(same as arm64). The s390x
librdkafka.redistruntime ships only the plainbuild, not a
centos8-variant.tools/wheels/build-wheels.sh: setCIBW_MANYLINUX_S390X_IMAGE="manylinux_2_28"so cibuildwheel builds s390x wheels in the same manylinux image as the other
Linux arches.
.semaphore/semaphore.yml: addWheels: Linux s390xandWheel Verification: Linux s390xblocks (natives1-ubuntu-24-s390x-4agent,mirroring the arm64 blocks) and wire the verification into the
Source Distributiondependencies.The Schema Registry serdes are pure Python and already ship in the wheel, so no
serdes code changes are required.
Checklist
arches are unaffected (the s390x branch/env var/blocks are additive).
Wheel Verificationblocks (tools/test-wheels.sh), which run the builtwheel's smoke tests in clean distro containers — the s390x block runs the
same verification.
Test & Review
Built the s390x wheel on a native IBM Z host via this exact path
(
export ARCH=s390x→tools/wheels/build-wheels.sh→ cibuildwheel →confluent_kafka-<ver>-cp312-cp312-manylinux_2_28_s390x.whl) and verified:across the glibc range manylinux_2_28 targets — AlmaLinux 8 (glibc 2.28, the
floor), RHEL/Rocky 9 (2.34), Ubuntu 24.04 (2.39).