Repository navigation
Ingest musl where the upstream publishes it (the layer half of #175) - #22
Conversation
The #175 decision had a producer half and a layer half. The producer half is
done across the org; this is the layer half, and it was not expressible until
varve v0.39.0 made `asset-for` values template-expanded.
Five tools move to statically linked musl on both Linux arches: synth, ordeal
and meld publish it today, and varve-producer and varve-serve gain it by
moving from v0.38.0 to v0.39.0, which is the first varve release to build musl
at all.
The key stays the gnu triple. `host_platform()` resolves every Linux host to
{arch}-unknown-linux-gnu, so a musl-keyed payload would match no host and fail
closed. A triple in this file is a platform KEY, not a libc claim — the same
shape the pulseengine-wasm realm already uses for wac.
The repo's own check-manifest caught what the bump missed: varve-core the
crate and varve-core-api the docs are also sourced from pulseengine/varve, and
leaving them at v0.38.0 would have checked one release's assets against
another's sums. They move too.
This does NOT lower the layer's floor. Portability is the maximum across
payloads, and rivet, spar, witness, loom, kiln and wsc are still gnu.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019TNtfRjLNhEz82G2ggeeNu
|
Security: added ordeal v0.22.0 → v0.22.1 to this branch.
This matters more here than in any single repo's CI: a layer is how the v0.22.1 publishes the same four Linux assets, so the musl mapping in this Two things this PR does not do, both needing the realm key:
|
varve#196: the rolling layer still ingested
-linux-gnufor every Linuxpayload, including for tools whose release already publishes a static musl
build. This is the layer half of the varve#175 decision.
It was not expressible before varve v0.39.0, which made
asset-forvaluestemplate-expanded (pulseengine/varve#199).
What changes
Every asset name was checked against the actual release listing, not inferred
from the pattern.
The key stays the gnu triple
host_platform()resolves every Linux host to{arch}-unknown-linux-gnu, so amusl-keyed payload would match no host and fail closed. A triple here is a
platform key, not a libc claim — the same shape
pulseengine-wasmalreadyuses for
wac.What the repo's own checker caught
check-manifest.pyrefused the first version of this:varve-core(crate) andvarve-core-api(docs) are also sourced frompulseengine/varveand had to move with the tools. Good gate.What this does NOT do
It does not lower the layer's floor. Portability is the maximum floor
across payloads, and rivet, spar, witness, loom, kiln and wsc still ship gnu
only — so a consumer on RHEL 9 or Alpine still cannot run the toolchain. That
needs the remaining upstreams: rivet#980, spar#447, witness#234, sigil#279,
loom#388, kiln#514.
Five of eleven is progress worth depositing, not a fix to announce.
🤖 Generated with Claude Code
https://claude.ai/code/session_019TNtfRjLNhEz82G2ggeeNu