Skip to content

ci: move off ubuntu-22.04 runners without changing the release glibc baseline - #6467

Draft
joshuarli wants to merge 1 commit into
masterfrom
ci-ubuntu-24-04-runners
Draft

joshuarli wants to merge 1 commit into
masterfrom
ci-ubuntu-24-04-runners

Conversation

@joshuarli

@joshuarli joshuarli commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Why

GitHub is retiring the Ubuntu 22.04 runner images: deprecation began September 17, 2026 (longer queue times), they are unsupported from April 17, 2027, with brownouts in March and April 2027 that deliberately fail ubuntu-22.04 jobs. See actions/runner-images#14254.

A plain ubuntu-22.04 -> ubuntu-24.04 swap would not be safe here: the Linux release binaries inherit the glibc of the machine that builds them, and build_binary.yml documents that Ubuntu 22.04 must stay supported until Apr 2029 (glibc 2.35 baseline; 24.04 is 2.39).

What changed

  1. build_binary.yml, linux-aarch64 (release binary): now runs on ubuntu-24.04-arm but builds inside an ubuntu:22.04 container. This mirrors the existing x86_64 linux job, which already builds in an ubuntu:20.04 container on ubuntu-latest. The glibc baseline now comes from the container, not from the runner image. The dependency install, git safe-directory and rustup steps are copied from the x86_64 job; artifact names and paths are unchanged.
  2. ci.yml, build and build-internal: ubuntu-22.04(-arm) -> ubuntu-24.04(-arm). These binaries only go into Docker images (Dockerfile.release, base dhi-mirror/static:20250419-glibc-debian13, glibc 2.41), so a glibc 2.39 build is compatible.

Deliberately not changed

  • The release glibc baseline: the aarch64 release binary is still built against Ubuntu 22.04's glibc 2.35, so the documented support policy and the operating-guidelines docs are unaffected.
  • The macos-14 lines (handled separately in ci: upgrade macos-14 runners to macos-15 #6466) and everything else.

Evidence

  • aarch64 release binary (validated with a temporary, since-removed pull_request trigger on this branch, run 37077568186, both Linux jobs green):
    • container: ldd (Ubuntu GLIBC 2.35-0ubuntu3.15) 2.35
    • binary: ELF 64-bit LSB pie executable, ARM aarch64 ... stripped, highest required symbol version GLIBC_2.34 (<= 2.35), no GLIBCXX requirement; NEEDED: libgcc_s.so.1, libm.so.6, libc.so.6.
  • Full CI on the final commit (run 37078465227, Trigger: Full-CI label so the arm64 and relay-pop paths run): 41 checks pass, 2 skipped (not applicable). This includes all eight Build (Internal) Relay Binary jobs on the new runners, Build Docker Image, Sentry-Relay Integration Tests and self-hosted-end-to-end, which run the Debian 13 image with the 24.04-built binary.

Risks / what to double-check

  • build_binary.yml only runs on release/** pushes, so the final workflow file has not run as such; it was validated through the temporary PR trigger on the same job definition. Worth a look at the next release build.
  • The aarch64 release job now installs its own toolchain (apt + rustup via curl) instead of using the runner's preinstalled one, like the x86_64 job; the Rust toolchain is stable at build time, as before.
  • Labels: skip-changelog (this is CI-only) and Trigger: Full-CI (to exercise the arm64 build path; can be removed).

Opened as a draft; not requesting review yet.

…baseline

GitHub is retiring the Ubuntu 22.04 runner images (unsupported April 17, 2027).

- build_binary.yml: build the aarch64 release binary in an ubuntu:22.04
  container on ubuntu-24.04-arm, mirroring the x86_64 job, which already builds
  in a container. The glibc baseline now comes from the container instead of the
  runner image.
- ci.yml: the Build (Internal) Relay Binary jobs feed Docker images based on
  Debian 13, so they can build directly on ubuntu-24.04(-arm).
@joshuarli joshuarli added Trigger: Full-CI Runs all CI steps in a PR skip-changelog labels Oct 2, 2026
@joshuarli
joshuarli force-pushed the ci-ubuntu-24-04-runners branch from 4fa168e to cd25dc1 Compare October 2, 2026 23:37

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog Trigger: Full-CI Runs all CI steps in a PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant