Skip to content

Replace broken docker/python2 CI with the fork's real Android build - #4

Merged
buffym merged 5 commits into
masterfrom
buffy/fix-ci-android-build
Jul 13, 2026
Merged

buffym merged 5 commits into
masterfrom
buffy/fix-ci-android-build

Conversation

@buffym

@buffym buffym commented Jul 3, 2026

Copy link
Copy Markdown
Member

Why

The "Build and test J2V8" workflow came with the upstream fork and fails on every push — it's what's keeping #3 red. It's a 2017-era build farm: it needs Python 2.7 on the runner (gone from ubuntu-latest, and actions/setup-python dropped 2.7 in 2023), its docker images are based on debian:stable (no python2 there anymore) and debian:jessie (whose apt sources no longer exist), and it uploads with upload-artifact@v1, which GitHub disabled in January 2025.

Why this approach

The obvious fix is to keep patching the old workflow until it runs again, but we don't build J2V8 that way anymore — resurrecting the docker/python2 machinery would have CI building artifacts we don't ship. Per Build_new.md, releases (e.g. 6.2.1-16kb.2) are built with rebuild_native.sh: compile the four Android ABIs from the committed V8 monolith with 16KB page alignment, verify with check_elf_alignment.sh, then ./gradlew assembleRelease. CI now runs exactly that, so a green check means the thing we actually release still builds.

What this PR does

  • build_and_test.yml: replaces the docker/python2 linux + android jobs with one job that runs rebuild_native.sh on ubuntu-latest — JDK 17 (AGP 8.7.3 requires it) and the runner's preinstalled NDK — and uploads the aar.
  • Drops the upstream Linux-jar job; we only ship the Android aar.
  • build_and_release.yml (manual dispatch): same checkout/setup-java/upload-artifact updates.
  • Actions pinned to full commit SHAs (checkout v6.0.3, setup-java v5.4.0, upload-artifact v7.0.1), matching the convention from the Socket rollout.

After this merges

#3 should rebase onto master and drop its own CI-fix commits (the setup-python 2.7 attempt, etc.). The now-unused python2 build_system/ + docker/ machinery can go in a later cleanup — left alone here to keep the diff reviewable.

The "Build and test J2V8" workflow was inherited from upstream and has
been failing on every push: it needs Python 2.7, which is gone from
ubuntu-latest runners and no longer installable via actions/setup-python,
its docker images are based on debian:stable/jessie whose package sources
no longer provide python2 (or no longer exist), and it uses
actions/checkout@v1 and upload-artifact@v1, which are deprecated/disabled.

This fork doesn't build that way anymore: releases are produced by
rebuild_native.sh (compiles the four Android ABIs from the committed V8
monolith with 16KB page alignment, then runs ./gradlew assembleRelease),
per Build_new.md. Make CI run that real build instead:

- build_and_test.yml: drop the docker/python2 linux and android jobs;
  build with rebuild_native.sh on ubuntu-latest with JDK 17 (AGP 8.7.3
  requires 17) and the runner's preinstalled NDK, then upload the aar.
- build_and_release.yml: same checkout/setup-java/upload-artifact and
  JDK updates for the manual release workflow, which packages the
  committed jniLibs.

Actions are pinned to full commit SHAs, matching the org convention.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@socket-security

socket-security Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

sgrammargs and others added 2 commits July 2, 2026 21:28
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The shared workflow (ynab/shared-actions#233) is gaining a required
GH_YBOT_TOKEN secret (it now checks out shared-actions to run its helper
actions from current main). `secrets: inherit` forwards the org secrets it
needs today and means this file never needs touching when the shared
workflow's secret needs change again.

Safe to merge immediately: inherit also satisfies the current version of
the shared workflow.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@buffym
buffym marked this pull request as ready for review July 3, 2026 01:30
@buffym
buffym requested a review from GrahamBorland July 3, 2026 01:30

@GrahamBorland GrahamBorland left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks reasonable but I'd like @Dimezis to take a look too!

@buffym
buffym requested a review from Dimezis July 8, 2026 14:29
@Dimezis

Dimezis commented Jul 13, 2026

Copy link
Copy Markdown
Collaborator

Looks ok, thanks for taking care of this

@buffym
buffym merged commit 59a2f6a into master Jul 13, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants