Skip to content

workflows: use uv, add riscv64 builds - #182

Open
threexc wants to merge 4 commits into
ICRAR:masterfrom
threexc:tgamblin/riscv64
Open

threexc wants to merge 4 commits into
ICRAR:masterfrom
threexc:tgamblin/riscv64

Conversation

@threexc

@threexc threexc commented Sep 15, 2026 •

Copy link
Copy Markdown

Update the workflows and pyproject.toml to use uv, then make use of RISE's Native RISC-V Runners to build ijson for riscv64. This requires enabling them for the repository as a GitHub Application. More info is available here: https://riscv-runners.riseproject.dev/

I tried a test run on my fork. You can review the results here: threexc#1

This is being done on behalf of RISE, using the RISC-V Wheels dashboard to track upstream support for the Python ecosystem.

Summary by Sourcery

Adopt uv across packaging workflows and add riscv64 testing and wheel builds.

New Features:

  • Add native RISC-V runner coverage for fast tests and Linux wheel builds.
  • Use the RISE package index to support RISC-V build dependencies.

Enhancements:

  • Standardize workflow Python setup and package installation on uv.
  • Configure cibuildwheel to use uv for build and test environments.

CI:

  • Extend scheduled CI and PyPI deployment workflows to test and build riscv64 artifacts.

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
- Use setup-uv instead of setup-python, since uv is generally faster and
  supports more architectures (e.g. riscv64)
- Use 'uv pip' and 'uv build' everywhere instead of 'pip' and 'python -m
  build'
- Add UV_* variables to environment for use with uv build frontend
- Add ubuntu-24.04-riscv runner label and riscv64 build variables

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
@sourcery-ai

sourcery-ai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Reviewer's Guide

The workflows are migrated to uv for Python setup, dependency installation, sdist creation, and cibuildwheel builds, while adding RISE native riscv64 runners and package-index configuration so RISC-V wheels and tests can be produced alongside existing platforms.

Sequence diagram for uv-based wheel and sdist publishing

sequenceDiagram
    participant Workflow as GitHub Actions
    participant UV as uv
    participant CIBW as cibuildwheel
    participant Index as RISE package index
    participant PyPI as PyPI

    Workflow->>UV: setup-uv
    Workflow->>UV: uv pip install build
    Workflow->>UV: uv build --sdist
    Workflow->>CIBW: build wheels with CIBW_BUILD_FRONTEND
    CIBW->>UV: install build dependencies
    UV->>Index: resolve packages using UV_EXTRA_INDEX_URL
    CIBW-->>Workflow: platform wheels
    Workflow->>PyPI: publish sdist and wheels
Loading

Flow diagram for riscv64 wheel generation

flowchart TD
    Start["Calculate wheel matrix"] --> Runner["ubuntu-24.04-riscv"]
    Runner --> Setup["Set CIBW_ARCHS to riscv64"]
    Setup --> Build["cibuildwheel uses uv frontend"]
    Build --> Env["Pass RISE index environment into Linux container"]
    Env --> Wheel["Upload riscv64 wheel artifact"]
Loading

File-Level Changes

Change Details Files
Adds native riscv64 coverage to wheel builds and fast tests.
  • Defines riscv64 architecture matrices and schedules jobs on the RISE Ubuntu RISC-V runner.
  • Enables the RISE package index and passes its environment into Linux cibuildwheel containers.
  • Keeps RISC-V builds and tests aligned with existing platform coverage.
.github/workflows/deploy-to-pypi.yml
.github/workflows/fast-built-and-test.yml
pyproject.toml
Standardizes workflow package installation and builds on uv.
  • Replaces setup-python and pip commands with the pinned setup-uv action and uv pip/uv build commands.
  • Configures cibuildwheel to use its uv build frontend and installs the frontend extra explicitly.
  • Updates cibuildwheel test dependency installation for uv-created environments without pip.
.github/workflows/deploy-to-pypi.yml
.github/workflows/fast-built-and-test.yml
pyproject.toml
Preserves memory-leak workflow behavior while making pip invocation explicit and configuring the supplemental index.
  • Uses python3 -m pip for package and test dependency installation.
  • Adds the RISE package index through PIP_EXTRA_INDEX_URL.
.github/workflows/memleak-tests.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've found 1 issue

Prompt for AI Agents
Please address the comments from this code review:

## Individual Comments

### Comment 1
<location path=".github/workflows/fast-built-and-test.yml" line_range="33-37" />
<code_context>

-      - uses: actions/setup-python@v7
-        name: Install Python
+      - name: Python ${{ matrix.config.python }}
+        uses: astral-sh/setup-uv@20cfd1bf945f4377ade1205e4dbc17946fc9a30d # v10.0.1
         with:
</code_context>
<issue_to_address>
**issue (bug_risk):** The workflows reference `matrix.config.python`, but the fast-test matrix defines `python_version` directly and the distribution jobs have no matrix at all. Consequently, fast-test setup-uv receives an empty Python version instead of the requested matrix version, and the distribution step labels render without a Python version.

**Suggested fix:** Use `${{ matrix.python_version }}` in the fast-test job and a literal `3.13` (or remove the expression) in the distribution step names.
</issue_to_address>

Sourcery assessment

Needs a human reviewer. 1 finding to address first, and the release and test workflows now silently allow an external package index to win dependency resolution via unsafe-best-match, so a compromised or incorrect package there could execute during builds and potentially be incorporated into published artifacts. Reverting the workflow would not recall any already-published wheels or packages produced under that dependency policy.

Blocking findings: .github/workflows/fast-built-and-test.yml:37


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Comment thread .github/workflows/fast-built-and-test.yml Outdated
- Use setup-uv instead of setup-python, since uv is faster and supports
  more architectures (e.g. riscv64) by default
- Add UV_* variables to the environment enabling binary wheel downloads
  from the RISE Python registry, if PyPI doesn't have them
- Use 'uv pip install' wherever 'pip install' is found
- Add the ubuntu-24.04-riscv runner label to the matrix

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Be more explicit about using the relevant interpreter's pip module in
case pip isn't on the path. Also pass the RISE package registry as an
environment variable, so that tests on riscv64 can find binary wheels to
download if they're not on PyPI.

Signed-off-by: Trevor Gamblin <tgamblin@baylibre.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant