From 6ed6ece19dc8d21b7e33a557d917b8cd0a104c79 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Jan=20H=C3=B8ydahl?= Date: Wed, 23 Sep 2026 23:49:42 +0200 Subject: [PATCH] Workaround for QEmu crashes --- .github/renovate.json | 13 +++++++++++-- .github/workflows/docker-nightly.yml | 9 +++++++++ 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/.github/renovate.json b/.github/renovate.json index 9d3410e71957..b2b71b6ff813 100644 --- a/.github/renovate.json +++ b/.github/renovate.json @@ -4,10 +4,19 @@ "enabled": true, "gitIgnoredAuthors": ["renovate-bot "], "dependencyDashboard": false, - "enabledManagers": ["gradle", "github-actions"], + "enabledManagers": ["gradle", "github-actions", "custom.regex"], "labels": ["exempt-stale"], "milestone": 1, "includePaths": ["gradle/libs.versions.toml", "ui/gradle/libs.versions.toml", "versions.*", "build.gradle", ".github/workflows/*"], + "customManagers": [ + { + "customType": "regex", + "description": "Bump container images pinned as action inputs (e.g. the QEMU emulator passed to docker/setup-qemu-action), which the github-actions manager does not track", + "managerFilePatterns": ["/^\\.github/workflows/.+\\.ya?ml$/"], + "matchStrings": ["image:\\s+(?[^\\s@]+)@(?sha256:[a-f0-9]+)\\s+#\\s*(?\\S+)"], + "datasourceTemplate": "docker" + } + ], "postUpgradeTasks": { "commands": [ "./gradlew resolveAndLockAll --write-locks", @@ -194,7 +203,7 @@ }, { "description": "Group all GitHub Actions upgrades together in same PR", - "matchManagers": ["github-actions"], + "matchManagers": ["github-actions", "custom.regex"], "groupName": "GitHub Actions" } ], diff --git a/.github/workflows/docker-nightly.yml b/.github/workflows/docker-nightly.yml index e72add897c8f..9ad8df4fdb90 100644 --- a/.github/workflows/docker-nightly.yml +++ b/.github/workflows/docker-nightly.yml @@ -120,8 +120,17 @@ jobs: production=true EOF + # qemu-user mis-maps some emulated arm64 allocations when the host randomizes them, + # segfaulting ldconfig during the linux/arm64 leg (tonistiigi/binfmt#298). + - name: Disable ASLR to work around QEMU arm64 segfaults + run: sudo sysctl -w kernel.randomize_va_space=0 + - name: Set up QEMU for multi-platform builds uses: docker/setup-qemu-action@96fe6ef7f33517b61c61be40b68a1882f3264fb8 # v4.2.0 + with: + # Pinned; the action otherwise pulls a floating :latest, and qemu version changes + # have caused intermittent segfaults in the emulated linux/arm64 build. + image: tonistiigi/binfmt@sha256:400a4873b838d1b89194d982c45e5fb3cda4593fbfd7e08a02e76b03b21166f0 # qemu-v10.2.3 - name: Set up Docker Buildx uses: docker/setup-buildx-action@37fe631027851001ddb9b187196cc803df7f5f0e # v4.3.0