Use prebuilt V8 archives for Bazel on macOS and GNU Linux (#47951)

## What changed

Select checksum-pinned `rusty_v8` 150.4.0 release archives and matching Rust bindings for x64 and arm64 macOS and GNU Linux when pointer compression and the V8 sandbox are enabled.

Add `--//:rusty_v8_from_source=true` to select source-built archives and bindings together for custom V8 C++ flags or instrumentation. Fall back to the existing source path when the sandbox or pointer compression settings differ from the published artifacts, and retain source builds for musl Linux and Windows GNU.

On GNU Linux, weaken the ten shared `std::logic_error` and `std::runtime_error` constructor and assignment symbols in the Bazel output so toolchain libc++ definitions take precedence. Preserve the checksum-verified inputs and constructors accepting `std::__Cr::string`.

Document artifact selection, source overrides, and checksum maintenance.

GitOrigin-RevId: cedd474c739ae16e07a78f35459d2c383e5781d8
This commit is contained in:
Ahmed Ibrahim
2026-09-24 22:33:01 +00:00
committed by copyberry
parent cf792c3a25
commit 4a358b1ae9
7 changed files with 225 additions and 17 deletions
+8
View File
@@ -1,4 +1,12 @@
load("@apple_support//xcode:xcode_config.bzl", "xcode_config")
load("@bazel_skylib//rules:common_settings.bzl", "bool_flag")
# Set for builds that need custom V8 C++ flags or source instrumentation.
bool_flag(
name = "rusty_v8_from_source",
build_setting_default = False,
visibility = ["//visibility:public"],
)
xcode_config(name = "disable_xcode")
+72
View File
@@ -833,6 +833,78 @@ http_file(
],
)
http_file(
name = "rusty_v8_150_4_0_aarch64_apple_darwin_archive",
downloaded_file_path = "librusty_v8_ptrcomp_sandbox_release_aarch64-apple-darwin.a.gz",
sha256 = "00adbb48798848c77550441c68673a5e8529b8e1b73eabcdee232cb39b40f4a1",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/librusty_v8_ptrcomp_sandbox_release_aarch64-apple-darwin.a.gz",
],
)
http_file(
name = "rusty_v8_150_4_0_aarch64_apple_darwin_binding",
downloaded_file_path = "src_binding_ptrcomp_sandbox_release_aarch64-apple-darwin.rs",
sha256 = "ca5adf0cf89c9a70ad460ae73648b2fe89b74aa113b3cb7f757b6a02b758394f",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/src_binding_ptrcomp_sandbox_release_aarch64-apple-darwin.rs",
],
)
http_file(
name = "rusty_v8_150_4_0_aarch64_unknown_linux_gnu_archive",
downloaded_file_path = "librusty_v8_ptrcomp_sandbox_release_aarch64-unknown-linux-gnu.a.gz",
sha256 = "d1517eed405468537029b005d5fe997ec74d5c8d351f916b3a6df20b7d2811ba",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/librusty_v8_ptrcomp_sandbox_release_aarch64-unknown-linux-gnu.a.gz",
],
)
http_file(
name = "rusty_v8_150_4_0_aarch64_unknown_linux_gnu_binding",
downloaded_file_path = "src_binding_ptrcomp_sandbox_release_aarch64-unknown-linux-gnu.rs",
sha256 = "7727826ae479bdb645e807239fb12d1f8e2e23de7a6cf16f5ee592690d1d8506",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/src_binding_ptrcomp_sandbox_release_aarch64-unknown-linux-gnu.rs",
],
)
http_file(
name = "rusty_v8_150_4_0_x86_64_apple_darwin_archive",
downloaded_file_path = "librusty_v8_ptrcomp_sandbox_release_x86_64-apple-darwin.a.gz",
sha256 = "e0d9bb64e8b3a034c2930c83972f3f35760211148342fa0407b38250ef330856",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/librusty_v8_ptrcomp_sandbox_release_x86_64-apple-darwin.a.gz",
],
)
http_file(
name = "rusty_v8_150_4_0_x86_64_apple_darwin_binding",
downloaded_file_path = "src_binding_ptrcomp_sandbox_release_x86_64-apple-darwin.rs",
sha256 = "ca5adf0cf89c9a70ad460ae73648b2fe89b74aa113b3cb7f757b6a02b758394f",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/src_binding_ptrcomp_sandbox_release_x86_64-apple-darwin.rs",
],
)
http_file(
name = "rusty_v8_150_4_0_x86_64_unknown_linux_gnu_archive",
downloaded_file_path = "librusty_v8_ptrcomp_sandbox_release_x86_64-unknown-linux-gnu.a.gz",
sha256 = "a35c75d1f26e6a983885a45b33490a4ebe54f05050568b32b89cfb421b30b583",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/librusty_v8_ptrcomp_sandbox_release_x86_64-unknown-linux-gnu.a.gz",
],
)
http_file(
name = "rusty_v8_150_4_0_x86_64_unknown_linux_gnu_binding",
downloaded_file_path = "src_binding_ptrcomp_sandbox_release_x86_64-unknown-linux-gnu.rs",
sha256 = "7727826ae479bdb645e807239fb12d1f8e2e23de7a6cf16f5ee592690d1d8506",
urls = [
"https://github.com/openai/codex/releases/download/rusty-v8-v150.4.0/src_binding_ptrcomp_sandbox_release_x86_64-unknown-linux-gnu.rs",
],
)
use_repo(crate, "crates")
bazel_dep(name = "libcap", version = "2.27.bcr.1")
+11 -4
View File
@@ -7,7 +7,7 @@ diff --git a/orig/v8-15.0.245.2/bazel/defs.bzl b/mod/v8-15.0.245.2/bazel/defs.bz
index bbe1495..6673518 100644
--- a/orig/v8-15.0.245.2/bazel/defs.bzl
+++ b/mod/v8-15.0.245.2/bazel/defs.bzl
@@ -33,9 +33,21 @@ _create_option_int = rule(
@@ -33,9 +33,25 @@ _create_option_int = rule(
)
def v8_flag(name, default = False):
@@ -30,8 +30,14 @@ index bbe1495..6673518 100644
+ visibility = ["//visibility:public"],
+ )
def v8_string(name, default = ""):
_create_option_string(name = name, build_setting_default = default)
-def v8_string(name, default = ""):
- _create_option_string(name = name, build_setting_default = default)
+def v8_string(name, default = "", visibility = None):
+ _create_option_string(
+ name = name,
+ build_setting_default = default,
+ visibility = visibility,
+ )
@@ -97,7 +109,13 @@ v8_config = rule(
def _default_args():
@@ -169,12 +175,13 @@ index b432f86..28c567b 100644
v8_flag(name = "v8_enable_verify_csa")
v8_flag(name = "v8_enable_verify_heap")
@@ -313,7 +317,7 @@ v8_int(
@@ -313,7 +317,8 @@ v8_int(
# If no explicit value for v8_enable_pointer_compression, we set it to 'none'.
v8_string(
name = "v8_enable_pointer_compression",
- default = "none",
+ default = "False",
+ visibility = ["//visibility:public"],
)
# Default setting for v8_enable_pointer_compression.
+82
View File
@@ -66,8 +66,69 @@ alias(
actual = ":src_binding_release_aarch64_unknown_linux_gnu_150_4_0_release",
)
# Published files contain both pointer compression and the in-process sandbox.
# Use the source pair together whenever those options differ or a caller needs
# custom V8 C++ flags. The main-repo flag is shared with the @v8_targets copy
# of this BUILD file used by rules_rs.
config_setting(
name = "use_rusty_v8_prebuilts",
flag_values = {
"@//:rusty_v8_from_source": "False",
"@v8//:v8_enable_pointer_compression": "True",
"@v8//:v8_enable_sandbox": "True",
},
)
alias(
name = "rusty_v8_archive_for_target",
actual = select({
":use_rusty_v8_prebuilts": ":rusty_v8_prebuilt_archive_for_target",
"//conditions:default": ":rusty_v8_source_archive_for_target",
}),
)
alias(
name = "rusty_v8_prebuilt_archive_for_target",
actual = select({
"@rules_rs//rs/platforms/config:aarch64-apple-darwin": "@rusty_v8_150_4_0_aarch64_apple_darwin_archive//file",
"@rules_rs//rs/platforms/config:aarch64-unknown-linux-gnu": ":v8_150_4_0_aarch64_unknown_linux_gnu_prebuilt",
"@rules_rs//rs/platforms/config:x86_64-apple-darwin": "@rusty_v8_150_4_0_x86_64_apple_darwin_archive//file",
"@rules_rs//rs/platforms/config:x86_64-unknown-linux-gnu": ":v8_150_4_0_x86_64_unknown_linux_gnu_prebuilt",
":platform_aarch64_unknown_linux_musl": ":rusty_v8_source_archive_for_target",
":platform_x86_64_unknown_linux_musl": ":rusty_v8_source_archive_for_target",
"//conditions:default": ":rusty_v8_source_archive_for_target",
}),
)
# A GNU Codex release archive carries Chromium's namespaced libc++ runtime.
# Bazel also links its own libc++. Both keep their exception classes in std::,
# so prefer the toolchain definitions of just those shared ABI entry points.
# Inputs remain checksum-verified and immutable; only the Bazel output changes.
[
genrule(
name = "v8_150_4_0_%s_unknown_linux_gnu_prebuilt" % arch,
srcs = [
":gnu_libcxx_shared_exception_symbols.txt",
"@rusty_v8_150_4_0_%s_unknown_linux_gnu_archive//file" % arch,
],
outs = ["libv8_150_4_0_%s_unknown_linux_gnu_prebuilt.a" % arch],
cmd = """
gzip -dc "$(location @rusty_v8_150_4_0_%s_unknown_linux_gnu_archive//file)" > "$@.unadjusted"
$(location @llvm//tools:llvm-objcopy) \
--weaken-symbols="$(location :gnu_libcxx_shared_exception_symbols.txt)" \
"$@.unadjusted" "$@"
rm "$@.unadjusted"
""" % arch,
tools = ["@llvm//tools:llvm-objcopy"],
)
for arch in [
"aarch64",
"x86_64",
]
]
alias(
name = "rusty_v8_source_archive_for_target",
actual = select({
"@rules_rs//rs/platforms/config:aarch64-apple-darwin": ":v8_150_4_0_aarch64_apple_darwin_bazel",
"@rules_rs//rs/platforms/config:aarch64-pc-windows-gnullvm": ":v8_150_4_0_aarch64_pc_windows_gnullvm",
@@ -85,6 +146,27 @@ alias(
alias(
name = "rusty_v8_binding_for_target",
actual = select({
":use_rusty_v8_prebuilts": ":rusty_v8_prebuilt_binding_for_target",
"//conditions:default": ":rusty_v8_source_binding_for_target",
}),
)
alias(
name = "rusty_v8_prebuilt_binding_for_target",
actual = select({
"@rules_rs//rs/platforms/config:aarch64-apple-darwin": "@rusty_v8_150_4_0_aarch64_apple_darwin_binding//file",
"@rules_rs//rs/platforms/config:aarch64-unknown-linux-gnu": "@rusty_v8_150_4_0_aarch64_unknown_linux_gnu_binding//file",
"@rules_rs//rs/platforms/config:x86_64-apple-darwin": "@rusty_v8_150_4_0_x86_64_apple_darwin_binding//file",
"@rules_rs//rs/platforms/config:x86_64-unknown-linux-gnu": "@rusty_v8_150_4_0_x86_64_unknown_linux_gnu_binding//file",
":platform_aarch64_unknown_linux_musl": ":rusty_v8_source_binding_for_target",
":platform_x86_64_unknown_linux_musl": ":rusty_v8_source_binding_for_target",
"//conditions:default": ":rusty_v8_source_binding_for_target",
}),
)
alias(
name = "rusty_v8_source_binding_for_target",
actual = select({
"@rules_rs//rs/platforms/config:aarch64-apple-darwin": ":src_binding_release_aarch64_apple_darwin_150_4_0_release",
"@rules_rs//rs/platforms/config:aarch64-pc-windows-gnullvm": ":src_binding_release_aarch64_pc_windows_gnullvm_150_4_0_release",
+31 -13
View File
@@ -3,18 +3,24 @@
This directory wires the `v8` crate to exact-version Bazel inputs.
Bazel consumer builds use:
- upstream `denoland/rusty_v8` release archives on Windows MSVC
- source-built V8 archives on Darwin, GNU Linux, musl Linux, and Windows GNU
- Codex-published sandbox archive/binding pairs on Darwin and GNU Linux (x64
and arm64), with checksums pinned from the trusted release manifests
- the existing Codex-published Windows MSVC archives
- source-built V8 archives on musl Linux and Windows GNU
Local Cargo builds still use upstream prebuilt `rusty_v8` archives by default.
Selected Cargo CI, release, and package builds override
`RUSTY_V8_ARCHIVE`/`RUSTY_V8_SRC_BINDING_PATH` with Codex release assets. Bazel
sets those variables independently in `MODULE.bazel` to select source-built
local archives and bindings for its consumer builds.
sets those variables independently in `MODULE.bazel`, selecting the pair above
for its consumers. All Bazel compilation modes use the same published V8
release archive on supported platforms.
The Bazel `v8` crate feature selection enables V8's in-process sandbox for
Darwin, Linux, and Windows GNU. Windows MSVC remains on upstream non-sandboxed
prebuilts.
The Bazel `v8` crate feature selection enables V8's in-process sandbox.
Darwin/GNU consumers select prebuilts only when both the V8 sandbox and pointer
compression settings match the published artifact. For source instrumentation
or custom V8 C++ settings, use `--//:rusty_v8_from_source=true`; the archive
and binding then both come from the source path. The published release archive
cannot incorporate local V8 C++ flags or native debug/sanitizer settings.
Current pinned versions:
@@ -36,7 +42,7 @@ Use this as the maintainer flow for a version bump:
6. Once the release build completes, rerun the build on the candidate branch
and verify that the final artifact builds and tests pass.
When changing the remaining prebuilt `rusty_v8` `http_file` inputs, keep the
When changing the prebuilt `rusty_v8` `http_file` inputs, keep the
checked-in checksum manifest and `MODULE.bazel` in sync:
```bash
@@ -44,9 +50,12 @@ python3 .github/scripts/rusty_v8_bazel.py update-module-bazel
python3 .github/scripts/rusty_v8_bazel.py check-module-bazel
```
The commands default to the single `rusty_v8_*` `http_file` version still
present in `MODULE.bazel` and validate every matching entry. CI runs the check
command to block checksum drift.
For the Darwin/GNU pairs, verify each published
`rusty_v8_ptrcomp_sandbox_release_<target>.sha256` against the committed
`rusty_v8_<version>_release_manifests.sha256` first. Copy the verified archive
and binding checksums into `rusty_v8_<version>.sha256`, then run these
commands. They validate every matching `http_file` entry, and CI blocks
checksum drift.
The consumer-facing selectors are:
@@ -101,8 +110,17 @@ the final static archive so consumers can link it with the `v8` crate's default
`use_custom_libcxx` feature. The config keeps the object files and the bundled
runtime on Chromium's `std::__Cr` ABI namespace instead of mixing those objects
with the toolchain libc++ default namespace. Bazel consumers use these
source-built targets directly; Cargo release and package builds use the
published copies.
published archives for supported Darwin/GNU platforms, as do Cargo release and
package builds. On GNU Linux, Bazel decompresses to a private output and weakens
the ten shared `std::logic_error` and `std::runtime_error` constructors and
assignment entry points listed in `gnu_libcxx_shared_exception_symbols.txt`.
libc++ keeps these exception functions in `std::` across inline ABI namespaces;
the toolchain's definitions then take precedence if both runtimes are linked.
Constructors accepting Chromium's `std::__Cr::string` remain strong in the V8
archive. The verified input and the producer's archive are never mutated.
This depends on libc++'s shared exception-object ABI; updates to either libc++
revision must keep the native GNU link/runtime checks passing. The Bazel pair targets above still point directly to source
targets so a new release or canary never depends on an older published copy.
MSVC is not part of the Bazel-produced matrix yet. The repository's current
hermetic Windows C++ platform is `windows-gnullvm`/`x86_64-w64-windows-gnu`, so
+13
View File
@@ -0,0 +1,13 @@
# libc++ intentionally leaves these exception functions in std:: across ABI
# namespaces. Prefer the Bazel toolchain definitions if both runtimes link.
# Keep constructors taking std::__Cr::string strong in the V8 archive.
_ZNSt11logic_errorC1EPKc
_ZNSt11logic_errorC1ERKS_
_ZNSt11logic_errorC2EPKc
_ZNSt11logic_errorC2ERKS_
_ZNSt11logic_erroraSERKS_
_ZNSt13runtime_errorC1EPKc
_ZNSt13runtime_errorC1ERKS_
_ZNSt13runtime_errorC2EPKc
_ZNSt13runtime_errorC2ERKS_
_ZNSt13runtime_erroraSERKS_
+8
View File
@@ -1,2 +1,10 @@
54722842af36b74248c403ff531254efac6ff65d281198bab0c6350fc1188ad4 rusty_v8_release_aarch64-pc-windows-msvc.lib.gz
732ec5da4243aa166799780c8519a5eea6f32f6e47657a323342794dc3c239d6 rusty_v8_release_x86_64-pc-windows-msvc.lib.gz
00adbb48798848c77550441c68673a5e8529b8e1b73eabcdee232cb39b40f4a1 librusty_v8_ptrcomp_sandbox_release_aarch64-apple-darwin.a.gz
ca5adf0cf89c9a70ad460ae73648b2fe89b74aa113b3cb7f757b6a02b758394f src_binding_ptrcomp_sandbox_release_aarch64-apple-darwin.rs
d1517eed405468537029b005d5fe997ec74d5c8d351f916b3a6df20b7d2811ba librusty_v8_ptrcomp_sandbox_release_aarch64-unknown-linux-gnu.a.gz
7727826ae479bdb645e807239fb12d1f8e2e23de7a6cf16f5ee592690d1d8506 src_binding_ptrcomp_sandbox_release_aarch64-unknown-linux-gnu.rs
e0d9bb64e8b3a034c2930c83972f3f35760211148342fa0407b38250ef330856 librusty_v8_ptrcomp_sandbox_release_x86_64-apple-darwin.a.gz
ca5adf0cf89c9a70ad460ae73648b2fe89b74aa113b3cb7f757b6a02b758394f src_binding_ptrcomp_sandbox_release_x86_64-apple-darwin.rs
a35c75d1f26e6a983885a45b33490a4ebe54f05050568b32b89cfb421b30b583 librusty_v8_ptrcomp_sandbox_release_x86_64-unknown-linux-gnu.a.gz
7727826ae479bdb645e807239fb12d1f8e2e23de7a6cf16f5ee592690d1d8506 src_binding_ptrcomp_sandbox_release_x86_64-unknown-linux-gnu.rs