Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .audit/ndabas_master.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
## AI Assistance Disclosure

- [ ] I did **not** use any AI-assistance tools to help create this pull request.
- [x] I **did** use AI-assistance tools to *help* create this pull request.
- [x] I have read, understood and followed the projects' [AI Policy](https://github.com/crossbario/autobahn-python/blob/main/AI_POLICY.md) when creating code, documentation etc. for this pull request.

Submitted by: @ndabas
Date: 2026-09-21
Related issue(s): #1936
Branch: ndabas:master
4 changes: 4 additions & 0 deletions .github/workflows/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,7 @@ including artifact production and consumption flow.
│ wheels.yml (native GitHub runners) │
│ ├── wheels-macos-arm64 (macOS ARM64 wheels) │
│ ├── wheels-windows-x86_64 (Windows x64 wheels) │
│ ├── wheels-windows-arm64 (Windows ARM64 wheels, CPython only) │
│ ├── linux-wheels-no-nvx (Linux pure Python wheels) │
│ └── source-distribution (*.tar.gz sdist) │
│ │
Expand Down Expand Up @@ -180,6 +181,7 @@ functionality to wheel installs including the flatc binary.
| **wstest.yml** | `wstest-results` | WebSocket conformance reports | N/A |
| **wheels.yml** | `wheels-macos-arm64` | macOS ARM64 wheels (cpy311-314, pypy311) | macOS arm64 |
| **wheels.yml** | `wheels-windows-x86_64` | Windows x64 wheels (cpy311-314, pypy311) | Windows x86_64 |
| **wheels.yml** | `wheels-windows-arm64` | Windows ARM64 wheels (cpy311-314, no PyPy) | Windows arm64 |
| **wheels.yml** | `linux-wheels-no-nvx` | Pure Python wheels (no NVX) | Linux x86_64 |
| **wheels.yml** | `source-distribution` | `*.tar.gz` sdist | Linux (build host) |
| **wheels-docker.yml** | `artifacts-manylinux_2_28_x86_64` | Linux x64 wheels (see below) | Linux x86_64 |
Expand All @@ -204,6 +206,7 @@ download action. It maps artifact names via the `check-workflows` job outputs:
|-----------------|-----------------|------------------|
| `artifact_macos_wheels` | wheels.yml | `wheels-macos-arm64` |
| `artifact_windows_wheels` | wheels.yml | `wheels-windows-x86_64` |
| `artifact_windows_arm64_wheels` | wheels.yml | `wheels-windows-arm64` |
| `artifact_source_dist` | wheels.yml | `source-distribution` |
| `artifact_linux_no_nvx` | wheels.yml | `linux-wheels-no-nvx` |
| `artifact_manylinux_x86_64` | wheels-docker.yml | `artifacts-manylinux_2_28_x86_64` |
Expand All @@ -223,6 +226,7 @@ download action. It maps artifact names via the `check-workflows` job outputs:
| Linux | aarch64 | PyPy 3.11 | manylinux_2_36/2_38 | wheels-arm64.yml |
| macOS | arm64 | 3.11, 3.12, 3.13, 3.14, PyPy 3.11 | N/A | wheels.yml |
| Windows | x86_64 | 3.11, 3.12, 3.13, 3.14, PyPy 3.11 | N/A | wheels.yml |
| Windows | arm64 | 3.11, 3.12, 3.13, 3.14 (no PyPy) | N/A | wheels.yml |

### Why Manylinux Containers?

Expand Down
53 changes: 50 additions & 3 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ jobs:
# Dynamic artifact names (with meta-checksum suffixes)
artifact_macos_wheels: ${{ steps.check.outputs.artifact_macos_wheels }}
artifact_windows_wheels: ${{ steps.check.outputs.artifact_windows_wheels }}
artifact_windows_arm64_wheels: ${{ steps.check.outputs.artifact_windows_arm64_wheels }}
artifact_source_dist: ${{ steps.check.outputs.artifact_source_dist }}
artifact_linux_no_nvx: ${{ steps.check.outputs.artifact_linux_no_nvx }}
artifact_manylinux_x86_64: ${{ steps.check.outputs.artifact_manylinux_x86_64 }}
Expand Down Expand Up @@ -139,6 +140,7 @@ jobs:
const wheelsRunId = latestRuns['wheels']?.id;
core.setOutput('artifact_macos_wheels', await findArtifact(wheelsRunId, 'wheels-macos-arm64'));
core.setOutput('artifact_windows_wheels', await findArtifact(wheelsRunId, 'wheels-windows-x86_64'));
core.setOutput('artifact_windows_arm64_wheels', await findArtifact(wheelsRunId, 'wheels-windows-arm64'));
core.setOutput('artifact_source_dist', await findArtifact(wheelsRunId, 'source-distribution'));
core.setOutput('artifact_linux_no_nvx', await findArtifact(wheelsRunId, 'linux-wheels-no-nvx'));

Expand Down Expand Up @@ -208,7 +210,7 @@ jobs:
retry-delay: 30
continue-on-error: true

- name: Download and verify Windows wheels with retry logic
- name: Download and verify Windows x86_64 wheels with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
name: ${{ needs.check-all-workflows.outputs.artifact_windows_wheels }}
Expand All @@ -219,6 +221,17 @@ jobs:
retry-delay: 30
continue-on-error: true

- name: Download and verify Windows ARM64 wheels with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
name: ${{ needs.check-all-workflows.outputs.artifact_windows_arm64_wheels }}
path: ${{ github.workspace }}/dist/
run-id: ${{ needs.check-all-workflows.outputs.wheels_run_id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
max-attempts: 5
retry-delay: 30
continue-on-error: true

- name: Download and verify source distribution with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
Expand Down Expand Up @@ -910,24 +923,28 @@ jobs:
cpy311-linux-x86_64-musllinux_1_2
cpy311-linux-aarch64-musllinux_1_2
cpy311-win-amd64
cpy311-win-arm64
cpy312-macos-arm64
cpy312-linux-x86_64-manylinux_2_28
cpy312-linux-aarch64-manylinux_2_28
cpy312-linux-x86_64-musllinux_1_2
cpy312-linux-aarch64-musllinux_1_2
cpy312-win-amd64
cpy312-win-arm64
cpy313-macos-arm64
cpy313-linux-x86_64-manylinux_2_28
cpy313-linux-aarch64-manylinux_2_28
cpy313-linux-x86_64-musllinux_1_2
cpy313-linux-aarch64-musllinux_1_2
cpy313-win-amd64
cpy313-win-arm64
cpy314-macos-arm64
cpy314-linux-x86_64-manylinux_2_28
cpy314-linux-aarch64-manylinux_2_28
cpy314-linux-x86_64-musllinux_1_2
cpy314-linux-aarch64-musllinux_1_2
cpy314-win-amd64
cpy314-win-arm64
pypy311-macos-arm64
pypy311-linux-x86_64-manylinux_2_28
pypy311-linux-aarch64-manylinux_2_17
Expand Down Expand Up @@ -1126,7 +1143,7 @@ jobs:
retry-delay: 30
continue-on-error: true

- name: Download and verify Windows wheels with retry logic
- name: Download and verify Windows x86_64 wheels with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
name: ${{ needs.check-all-workflows.outputs.artifact_windows_wheels }}
Expand All @@ -1137,6 +1154,17 @@ jobs:
retry-delay: 30
continue-on-error: true

- name: Download and verify Windows ARM64 wheels with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
name: ${{ needs.check-all-workflows.outputs.artifact_windows_arm64_wheels }}
path: ${{ github.workspace }}/dist/
run-id: ${{ needs.check-all-workflows.outputs.wheels_run_id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
max-attempts: 5
retry-delay: 30
continue-on-error: true

- name: Download and verify source distribution with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
Expand Down Expand Up @@ -1828,24 +1856,28 @@ jobs:
cpy311-linux-x86_64-musllinux_1_2
cpy311-linux-aarch64-musllinux_1_2
cpy311-win-amd64
cpy311-win-arm64
cpy312-macos-arm64
cpy312-linux-x86_64-manylinux_2_28
cpy312-linux-aarch64-manylinux_2_28
cpy312-linux-x86_64-musllinux_1_2
cpy312-linux-aarch64-musllinux_1_2
cpy312-win-amd64
cpy312-win-arm64
cpy313-macos-arm64
cpy313-linux-x86_64-manylinux_2_28
cpy313-linux-aarch64-manylinux_2_28
cpy313-linux-x86_64-musllinux_1_2
cpy313-linux-aarch64-musllinux_1_2
cpy313-win-amd64
cpy313-win-arm64
cpy314-macos-arm64
cpy314-linux-x86_64-manylinux_2_28
cpy314-linux-aarch64-manylinux_2_28
cpy314-linux-x86_64-musllinux_1_2
cpy314-linux-aarch64-musllinux_1_2
cpy314-win-amd64
cpy314-win-arm64
pypy311-macos-arm64
pypy311-linux-x86_64-manylinux_2_28
pypy311-linux-aarch64-manylinux_2_17
Expand Down Expand Up @@ -2064,7 +2096,7 @@ jobs:
retry-delay: 30
continue-on-error: true

- name: Download and verify Windows wheels with retry logic
- name: Download and verify Windows x86_64 wheels with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
name: ${{ needs.check-all-workflows.outputs.artifact_windows_wheels }}
Expand All @@ -2075,6 +2107,17 @@ jobs:
retry-delay: 30
continue-on-error: true

- name: Download and verify Windows ARM64 wheels with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
name: ${{ needs.check-all-workflows.outputs.artifact_windows_arm64_wheels }}
path: ${{ github.workspace }}/dist/
run-id: ${{ needs.check-all-workflows.outputs.wheels_run_id }}
github-token: ${{ secrets.GITHUB_TOKEN }}
max-attempts: 5
retry-delay: 30
continue-on-error: true

- name: Download and verify source distribution with retry logic
uses: wamp-proto/wamp-cicd/actions/download-artifact-verified@main
with:
Expand Down Expand Up @@ -2537,24 +2580,28 @@ jobs:
cpy311-linux-x86_64-musllinux_1_2
cpy311-linux-aarch64-musllinux_1_2
cpy311-win-amd64
cpy311-win-arm64
cpy312-macos-arm64
cpy312-linux-x86_64-manylinux_2_28
cpy312-linux-aarch64-manylinux_2_28
cpy312-linux-x86_64-musllinux_1_2
cpy312-linux-aarch64-musllinux_1_2
cpy312-win-amd64
cpy312-win-arm64
cpy313-macos-arm64
cpy313-linux-x86_64-manylinux_2_28
cpy313-linux-aarch64-manylinux_2_28
cpy313-linux-x86_64-musllinux_1_2
cpy313-linux-aarch64-musllinux_1_2
cpy313-win-amd64
cpy313-win-arm64
cpy314-macos-arm64
cpy314-linux-x86_64-manylinux_2_28
cpy314-linux-aarch64-manylinux_2_28
cpy314-linux-x86_64-musllinux_1_2
cpy314-linux-aarch64-musllinux_1_2
cpy314-win-amd64
cpy314-win-arm64
pypy311-macos-arm64
pypy311-linux-x86_64-manylinux_2_28
pypy311-linux-aarch64-manylinux_2_17
Expand Down
52 changes: 37 additions & 15 deletions .github/workflows/wheels.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,13 +66,14 @@ jobs:
# I. GitHub's runner availability is... "special":
#
# ✅ ALWAYS AVAILABLE (Fast, < 30 seconds):
# - ubuntu-* (x86_64) → Abundant, instant
# - windows-* (x86_64) → Reliable, quick
# - macos-15 (ARM64) → Apple Silicon, readily available
# - ubuntu-* (x86_64) → Abundant, instant
# - windows-* (x86_64) → Reliable, quick
# - windows-11-arm (ARM64) → Smaller pool but still available
# - macos-15 (ARM64) → Apple Silicon, readily available
#
# 🕐 "PLEASE WAIT FOREVER" ZONE (Often > 1 hour waits):
# - ubuntu-*-arm64 → Limited pool, beta status
# - macos-12/13 (Intel) → Legacy hardware, being phased out
# - ubuntu-*-arm64 → Limited pool, beta status
# - macos-12/13 (Intel) → Legacy hardware, being phased out
#
# WHY THIS HAPPENS:
# 1. GitHub prioritizes current hardware (ARM64 macOS > Intel macOS)
Expand Down Expand Up @@ -102,6 +103,11 @@ jobs:
platform: windows
arch: x86_64

# --- Windows ---
- os: windows-11-arm # ✅ GitHub-hosted Windows ARM64 (mostly fast)
platform: windows
arch: arm64

# --- Linux ---
# - os: ubuntu-24.04-arm64 # 🕐 Linux ARM64 (servers/edge, often waits forever)
# platform: linux
Expand All @@ -112,12 +118,6 @@ jobs:
# platform: macos
# arch: x86_64

# --- Windows ---
# ⚠️ GitHub does NOT provide Windows ARM64 hosted runners.
# If you want Windows ARM64 builds, you must either:
# - run a self-hosted Windows ARM64 runner, OR
# - cross-compile from AMD64 to ARM64 inside the workflow.

steps:
- name: Checkout code
uses: actions/checkout@v4
Expand All @@ -136,7 +136,7 @@ jobs:
# we need to use this install wrapper on inheritently broken platforms (windows/powershell).
- name: Install Just (Windows)
if: runner.os == 'Windows'
uses: extractions/setup-just@v3
uses: extractions/setup-just@v4
with:
just-version: "1.42.3"
github-token: ${{ secrets.GITHUB_TOKEN }}
Expand All @@ -152,11 +152,11 @@ jobs:
echo "$HOME/.cargo/bin" >> $GITHUB_PATH

# we need to use this install wrapper on inheritently broken platforms (windows/powershell).
# Unpinned, like the Linux/macOS path.
- name: Install uv (Windows)
if: runner.os == 'Windows'
uses: astral-sh/setup-uv@v6
uses: astral-sh/setup-uv@v10.0.1
with:
version: "0.7.19"
enable-cache: true
github-token: ${{ secrets.GITHUB_TOKEN }}

Expand Down Expand Up @@ -487,6 +487,18 @@ jobs:
run: sync
shell: bash

- name: Build OpenSSL for cryptography (Windows ARM64 only)
# cryptography publishes no win_arm64 wheel, so pip builds it from
# source here and its openssl-sys build needs a native OpenSSL to link.
# WoA support has been added in https://github.com/pyca/cryptography/pull/15350
# This step can be removed when they publish a release.
if: matrix.os == 'windows-11-arm'
shell: pwsh
run: |
vcpkg install --triplet arm64-windows-static-md --clean-after-build openssl
"OPENSSL_DIR=$env:VCPKG_INSTALLATION_ROOT\installed\arm64-windows-static-md" |
Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append

- name: Build binary wheels with NVX (Windows)
if: matrix.platform == 'windows'
run: |
Expand All @@ -512,7 +524,7 @@ jobs:
"=========================================================" | Out-File -FilePath $validationFile -Append -Encoding UTF8
"" | Out-File -FilePath $validationFile -Append -Encoding UTF8
"Validation Date: $((Get-Date).ToUniversalTime().ToString('yyyy-MM-dd HH:mm:ss UTC'))" | Out-File -FilePath $validationFile -Append -Encoding UTF8
"Platform: Windows x86_64 (binary with NVX)" | Out-File -FilePath $validationFile -Append -Encoding UTF8
"Platform: Windows ${{ matrix.arch }} (binary with NVX)" | Out-File -FilePath $validationFile -Append -Encoding UTF8
"Python: $(python --version)" | Out-File -FilePath $validationFile -Append -Encoding UTF8
"twine: $(twine --version)" | Out-File -FilePath $validationFile -Append -Encoding UTF8
"" | Out-File -FilePath $validationFile -Append -Encoding UTF8
Expand Down Expand Up @@ -600,6 +612,16 @@ jobs:
Get-ChildItem dist
shell: pwsh

# Runs on every build platform. Building only proves the extension compiles;
# `just test-wheels` installs each wheel into an ephemeral venv and runs the
# shared smoke tests against the shipped artifact. The two expectations are
# passed in because the build cannot derive them itself: Linux builds with
# AUTOBAHN_USE_NVX=0, and matrix.arch is what pins down the emulation trap
# where an x86_64 interpreter on the ARM64 runner yields win_amd64 wheels.
- name: Smoke test built wheels
shell: bash
run: just test-wheels ${{ matrix.platform == 'linux' && '0' || '1' }} ${{ matrix.arch }}

- name: Upload wheel artifacts with cryptographic verification
uses: wamp-proto/wamp-cicd/actions/upload-artifact-verified@main
with:
Expand Down
Loading
Loading