You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
protect-ffi's release build has two gaps that the @cipherstash/auth build had until #1018.
Its C library check runs only in the preflight
ffi-preflight.yml reads which C library each Linux binary links, but nothing starts that dry run automatically. release.yml builds through _build-ffi-artifacts.yml and publishes without the check. So if the musl build stopped linking musl, a release would publish a binary that fails to load on musl systems such as Alpine Linux. That is how the suite published a glibc-linked @cipherstash/auth-linux-x64-musl 0.44.0.
Its musl toolchain comes from musl.cc
_build-ffi-artifacts.yml downloads its musl toolchain from musl.cc. On 2 October 2026, that download timed out from GitHub's runners on six tries in a row, although musl.cc answered from elsewhere. protect-ffi's next release, which #1014 will start, fails at that download if musl.cc is still unreachable.
Fix
Add the same C library step as fix(ci): build the musl @cipherstash/auth binary in Alpine, and check every binary's C library #1018: after each Linux build, read the binary's required libraries with readelf -d. The gnu binaries must require libc.so.6, and the musl binary must not. Add a test like the one in scripts/__tests__/auth-build-artifacts.test.mjs, which checks that the step comes before packing.
Each Linux leg of _build-ffi-artifacts.yml now runs scripts/check-c-library.sh on its binary before packing.
The linux-x64-musl binary now builds inside the same digest-pinned node:22-alpine image as @cipherstash/auth, and the build loads it with Node.js on musl. The build no longer downloads anything from musl.cc.
Both mise steps in _build-ffi-artifacts.yml now pin mise 2026.4.0. mise 2026.10.0, released on 2 October 2026, broke both gnu builds on main.
After it merged, ffi-preflight.yml passed against main, in run 37083686113.
protect-ffi's release build has two gaps that the
@cipherstash/authbuild had until #1018.Its C library check runs only in the preflight
ffi-preflight.ymlreads which C library each Linux binary links, but nothing starts that dry run automatically.release.ymlbuilds through_build-ffi-artifacts.ymland publishes without the check. So if the musl build stopped linking musl, a release would publish a binary that fails to load on musl systems such as Alpine Linux. That is how the suite published a glibc-linked@cipherstash/auth-linux-x64-musl0.44.0.Its musl toolchain comes from musl.cc
_build-ffi-artifacts.ymldownloads its musl toolchain from musl.cc. On 2 October 2026, that download timed out from GitHub's runners on six tries in a row, although musl.cc answered from elsewhere. protect-ffi's next release, which #1014 will start, fails at that download if musl.cc is still unreachable.Fix
readelf -d. The gnu binaries must requirelibc.so.6, and the musl binary must not. Add a test like the one inscripts/__tests__/auth-build-artifacts.test.mjs, which checks that the step comes before packing.@cipherstash/auth, or host a copy of the toolchain with its pinned digest.Fixed by #1027
#1027 merged on 3 October 2026:
_build-ffi-artifacts.ymlnow runsscripts/check-c-library.shon its binary before packing.linux-x64-muslbinary now builds inside the same digest-pinnednode:22-alpineimage as@cipherstash/auth, and the build loads it with Node.js on musl. The build no longer downloads anything from musl.cc._build-ffi-artifacts.ymlnow pin mise 2026.4.0. mise 2026.10.0, released on 2 October 2026, broke both gnu builds onmain.After it merged,
ffi-preflight.ymlpassed againstmain, in run 37083686113.