Skip to content

Fix release build: native ARM runner and proper failure detection - #140

Merged
go-kazuhiko-yamashita merged 2 commits into
masterfrom
fix/build
Aug 25, 2026
Merged

go-kazuhiko-yamashita merged 2 commits into
masterfrom
fix/build

Conversation

@go-kazuhiko-yamashita

@go-kazuhiko-yamashita go-kazuhiko-yamashita commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

背景

Release ワークフローの arm64 ジョブが終わらなくなっていた (32815416360 は build ステップで 1h50m 停滞)。調べる過程で、リリースにパッケージが公開されていないという別の問題も判明した。

タグ 公開された deb/rpm ジョブ結果
v2.6.8 amd64 / arm64 とも公開 success
v2.6.9 tar.gz のみ、deb/rpm なし success
v2.6.10 tar.gz のみ、deb/rpm なし success
v2.6.11 amd64 のみ、arm64 なし success

原因は 2 つある。

1. arm64 を QEMU エミュレーションでビルドしていた

arm64 は docker/setup-qemu-action による aarch64 エミュレーション上で、7 ディストリ分の openssl / curl / zlib をソースからフルビルドしていた。常に amd64 の 5 倍前後かかり、負荷次第で頭打ちになる。timeout-minutes: 1440 のため、停滞すると丸一日 runner を占有する。

flowchart LR
  subgraph before["変更前"]
    A1[ubuntu-latest<br/>x86_64] --> A2[QEMU<br/>aarch64 emulation] --> A3[7 distro × openssl/curl/zlib<br/>48分〜停滞]
  end
  subgraph after["変更後"]
    B1[ubuntu-24.04-arm<br/>native aarch64] --> B3[7 distro × openssl/curl/zlib]
  end
Loading

2. build.sh がコンテナの失敗を握り潰していた

各ディストロのコンテナを素の docker compose up で起動し、その終了コードも wait の結果も捨てていた。docker compose up は --exit-code-from を付けないとコンテナの失敗を終了コードに反映しないため、ビルドが全滅しても make pkg は成功し、ghr が中身の無い builds/ をそのまま公開して終わっていた。上表の v2.6.9 以降がこれにあたる。

flowchart TD
  C[distro container<br/>build 失敗] -->|exit 1| D["docker compose up<br/>(--exit-code-from なし)"]
  D -->|exit 0| E["build.sh<br/>wait の結果を破棄"]
  E -->|exit 0| F[make pkg 成功]
  F --> G[ghr が空の builds/ を公開]
  G --> H[パッケージ無しでリリース完了]
Loading

変更内容

.github/workflows/release.yml

  • arm64 を ubuntu-24.04-arm のネイティブ ARM runner で実行する。matrix を include 形式にして runs-on をアーキごとに切り替え、QEMU セットアップステップを削除
  • ghr のダウンロードを matrix.arch 追従に変更。linux_amd64 固定だったものが、ネイティブ ARM runner では実行できないため
  • timeout-minutes を 1440 → 120 に短縮

build.sh

  • docker compose up に --exit-code-from を渡し、コンテナの失敗を compose の終了コードに反映
  • バックグラウンドジョブの終了コードを wait で回収し、1 つでも失敗したら exit 1
  • イメージの docker compose build 失敗も記録し、そのサービスは起動しない

動作確認

build.sh を軽量な compose ファイル (busybox) に差し替えて検証した。

ケース 期待 結果
全サービス成功 exit 0 ✅ exit 0
1 サービスが exit 3 exit 1 + 失敗サービス名 ✅ exit 1 / The following services failed: b
同ケースを変更前の build.sh で実行 (回帰の確認) ⚠️ exit 0 — 失敗を握り潰すことを再現
7 サービス並列 (CONCURRENT_LIMIT=5) 同時実行 5 以下・全完了 ✅ 最大 5 / 7 件完了 / exit 0

release.yml は YAML をパースしてジョブ定義を検証済み。ghr v0.16.2 に linux_arm64 アセットが存在することも確認済み。実際のリリースビルドはタグ push 時に走るため、所要時間とパッケージの公開はマージ後の次リリースで確認したい。

The arm64 release job emulated aarch64 via QEMU, which made the
per-distro openssl/curl/zlib builds take hours and occasionally stall
(timeout-minutes was 1440, so a stuck run held a runner for a day).

- Run the arm64 matrix leg on ubuntu-24.04-arm (free for public repos)
  and drop the QEMU setup step
- Fetch the ghr binary matching the runner architecture; it was pinned
  to linux_amd64, which only worked because the host was x86_64
- Lower timeout-minutes to 120 so a stalled build fails fast
build.sh started each distro container with a bare `docker compose up`
and discarded both its exit code and the result of `wait`. Since
`docker compose up` does not propagate a container failure without
--exit-code-from, a distro whose build broke still left `make pkg`
successful, and ghr published a release with the packages missing.
v2.6.9 and v2.6.10 shipped with no deb/rpm at all, and v2.6.11 with
amd64 only, while every job reported success.

- Pass --exit-code-from so a failing container fails its compose run
- Collect the exit status of each background job via wait and exit 1
  when any service failed
- Record image build failures too, and skip starting those services
@go-kazuhiko-yamashita go-kazuhiko-yamashita changed the title Build arm64 packages on native ARM runner instead of QEMU Fix release build: native ARM runner and proper failure detection Aug 25, 2026
@go-kazuhiko-yamashita
go-kazuhiko-yamashita merged commit e10cb40 into master Aug 25, 2026
1 check passed
@go-kazuhiko-yamashita
go-kazuhiko-yamashita deleted the fix/build branch August 25, 2026 10:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants