Files
orca/config/scripts/pinned-node-downloads.mjs
T
OrcaWinandm4air ddd4927a0b build(orcad): server node-pty slots at glibc 2.28, plus a glibc 2.17 compat slot (#24134)
* build(orcad): build server glibc slots on glibc 2.28 and add the glibc 2.17 compat slot

Design D6: the default linux-{x64,arm64}-glibc node-pty slots now build in
manylinux_2_28 (digest-pinned) and are gated at glibc 2.28 / GLIBCXX_3.4.25
through a floor profile on verify-linux-glibc-floor.cjs; the desktop keeps
its Ubuntu 20.04 (2.31) default.

Adds the opt-in linux-x64-glibc217 compat target: NODE_RUNTIME_COMPAT_ASSETS
pins the unofficial glibc-217 Node (update/check pin scripts cover it, outside
SERVER_TARGETS), and a new CI lane builds the compat slot in manylinux2014
with static libstdc++, gates it at glibc 2.17 with no shared C++ runtime in
DT_NEEDED, and smokes it under the glibc-217 Node.

* refactor(node-runtime-pin): route compat lookups through isCompatServerTarget; keep the glibc doc's slot-name paragraph intact

---------

Co-authored-by: m4air <m4air@m4airs-Air.localdomain>
2026-10-01 01:10:57 -07:00

94 lines
3.6 KiB
JavaScript

// Hash-verified downloads of the pinned Node's build inputs (headers, node.lib) and executable.
import { chmodSync, copyFileSync, existsSync, mkdirSync, rmSync } from 'node:fs'
import { join, resolve } from 'node:path'
import {
NODE_RUNTIME_PIN,
isWindowsServerTarget,
nodeRuntimeAsset,
nodeRuntimeExecutablePath,
nodeRuntimeHeadersUrl,
nodeRuntimeReleaseUrl
} from '../../src/shared/node-runtime-pin.ts'
import { download, extract, sha256File } from './update-node-runtime-pin.mjs'
const ROOT = resolve(import.meta.dirname, '..', '..')
export function pinnedNodeCacheDir(env = process.env) {
return env.ORCA_NODE_RUNTIME_CACHE_DIR || join(ROOT, 'out', 'node-runtime-cache')
}
/** Reuses a cached file only when it still hashes to the pin; anything else is re-fetched. */
export async function fetchPinnedFile({ url, destination, sha256 }) {
if (existsSync(destination) && (await sha256File(destination)) === sha256) {
return destination
}
mkdirSync(join(destination, '..'), { recursive: true })
const partial = `${destination}.partial-${process.pid}`
await download(url, partial)
const actual = await sha256File(partial)
if (actual !== sha256) {
rmSync(partial, { force: true })
throw new Error(`${url} hashed ${actual}, but the Node runtime pin expects ${sha256}`)
}
rmSync(destination, { force: true })
copyFileSync(partial, destination)
rmSync(partial, { force: true })
return destination
}
/**
* A node-gyp `--nodedir` for `target`, built from the pinned headers tarball.
*
* Why per target: on Windows node-gyp links `<nodedir>/Release/node.lib`, which differs by
* arch and is not in the headers tarball.
*/
export async function preparePinnedNodeDir({ target, workDir, cacheDir = pinnedNodeCacheDir() }) {
const { version, headers } = NODE_RUNTIME_PIN
const tarball = await fetchPinnedFile({
url: nodeRuntimeHeadersUrl(),
destination: join(cacheDir, headers.file),
sha256: headers.sha256
})
rmSync(workDir, { recursive: true, force: true })
extract(tarball, workDir, `node-v${version}/include`)
const nodeDir = join(workDir, `node-v${version}`)
if (isWindowsServerTarget(target)) {
const lib = NODE_RUNTIME_PIN.windowsImportLibs[target]
const cached = await fetchPinnedFile({
url: nodeRuntimeReleaseUrl('official', lib.file, version),
destination: join(cacheDir, `node-v${version}-${lib.file.replace('/', '-')}`),
sha256: lib.sha256
})
mkdirSync(join(nodeDir, 'Release'), { recursive: true })
copyFileSync(cached, join(nodeDir, 'Release', 'node.lib'))
}
return nodeDir
}
/** The pinned `node` for a default or compat `target`, verified against both hashes. */
export async function ensurePinnedNodeExecutable({ target, cacheDir = pinnedNodeCacheDir() }) {
const asset = nodeRuntimeAsset(target)
if (!asset) {
throw new Error(`The Node runtime pin has no asset for ${target}`)
}
const member = nodeRuntimeExecutablePath(target, asset.archive)
const executable = join(cacheDir, member)
if (existsSync(executable) && (await sha256File(executable)) === asset.executableSha256) {
return executable
}
const archive = await fetchPinnedFile({
url: nodeRuntimeReleaseUrl(asset.source, asset.archive),
destination: join(cacheDir, asset.archive),
sha256: asset.archiveSha256
})
extract(archive, cacheDir, member)
const actual = await sha256File(executable)
if (actual !== asset.executableSha256) {
throw new Error(`${member} hashed ${actual}, but the pin expects ${asset.executableSha256}`)
}
if (process.platform !== 'win32') {
chmodSync(executable, 0o755)
}
return executable
}