Skip to content

Add static coglet binaries for Linux - #3184

Draft
michaeldwan wants to merge 3 commits into
mainfrom
md/coglet-binary
Draft

michaeldwan wants to merge 3 commits into
mainfrom
md/coglet-binary

Conversation

@michaeldwan

Copy link
Copy Markdown
Contributor

Adds a standalone coglet executable for Linux, built as static musl binaries for x86_64 and arm64. For now it only supports coglet --version.

  • mise run build:coglet:binary builds dist/coglet_Linux_x86_64 and dist/coglet_Linux_arm64 with cargo-zigbuild.
  • A build-coglet-binary CI job builds both and uploads them as an artifact.
  • Tagged releases attach both binaries and add them to checksums.txt.

The coglet crate gains a `coglet` executable. It supports
`coglet --version`, which prints the crate version; any other arguments
print usage and exit 2.

`mise run build:coglet:binary` cross-compiles it with cargo-zigbuild for
x86_64 and aarch64 musl, producing statically linked executables at
dist/coglet_Linux_x86_64 and dist/coglet_Linux_arm64 that run in any
Linux image, with or without Python. The musl targets are added to the
Rust toolchain in mise.toml.

Refs: 346s7yn1v8ww34r6
A `build-coglet-binary` job runs `mise run build:coglet:binary`, checks
that the x86_64 binary runs, and uploads both Linux binaries as the
CogletBinaries artifact. It is part of the CI Complete gate, so a broken
binary build fails CI.

Refs: w43pxy6jzvxb6zex
Tagged releases build the static coglet binaries and attach them as
coglet_Linux_x86_64 and coglet_Linux_arm64, next to the CLI binaries
and wheels. Their sha256 sums are appended to checksums.txt.

Refs: tbjybk16tyb19hvv

@ask-bonk ask-bonk Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Adds static musl coglet binaries (coglet_Linux_x86_64 / coglet_Linux_arm64) via cargo zigbuild, with a new mise run build:coglet:binary task, a CI job that builds/uploads them, and release wiring to attach them and append their checksums. Structure, naming, and reuse of existing COGLET_VERSION are all consistent with the repo. One suggestion below; also noting (not blocking) that this new job is a required ci-complete gate that rebuilds two release-mode musl targets on every PR since dist/ is never present in a fresh checkout.

Comment thread .github/workflows/ci.yaml
run: mise run build:coglet:binary
- name: Check coglet binary runs
run: |
file dist/coglet_Linux_x86_64 dist/coglet_Linux_arm64

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The file check prints the binary type but nothing fails if the binaries are dynamically linked — yet "static musl" is the entire point of this artifact. If the musl build ever regresses (e.g. a dependency forces a dynamic link), CI still passes and releases ship non-static binaries. Assert it:

Suggested change
file dist/coglet_Linux_x86_64 dist/coglet_Linux_arm64
file dist/coglet_Linux_x86_64 dist/coglet_Linux_arm64
file dist/coglet_Linux_x86_64 | grep -q "statically linked"
file dist/coglet_Linux_arm64 | grep -q "statically linked"
dist/coglet_Linux_x86_64 --version

@ask-bonk

ask-bonk Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Review: 1 finding (1 suggestion).

I'm Bonk, and I've done a quick review of your PR.

Summary: Adds static musl coglet Linux binaries (x86_64 + arm64) via cargo zigbuild, a new mise run build:coglet:binary task, a CI build/upload job, and release wiring to attach both binaries and append their checksums to checksums.txt.

Findings:

  1. Suggestion (posted inline, .github/workflows/ci.yaml:230): The file check in the build-coglet-binary job is informational only — it won't fail if the binaries are dynamically linked, which is the exact property this PR is meant to guarantee. Assert statically linked in the check step so CI enforces it.

Non-blocking note (not posted): the new build-coglet-binary job is a required ci-complete gate that will rebuild two release-mode musl targets on every PR (since dist/ is never present in a fresh checkout), adding meaningful build time to each PR's critical path. Consider gating it on changes under crates/ if that cost is undesirable.

Everything else checked out: coglet::COGLET_VERSION is exported from the lib, the mise task sources/outputs and crates/target paths are correct, the release artifact names line up with the download/copy steps, and the checksums append matches goreleaser's format.

github run

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant