From c57e67ce976cc93f542c06f7cc5e7b87d3e9b2e5 Mon Sep 17 00:00:00 2001 From: Jarred Sumner Date: Wed, 16 Sep 2026 01:31:22 +0000 Subject: [PATCH 1/3] CI: build with LLVM 23 The toolchain images move from clang/lld 21 to 23. - llvm-23-debs (mirror-llvm-debs workflow, focal amd64/arm64 + noble amd64), compiler-rt-darwin-23.1.1 and compiler-rt-windows-23.1.1 (extracted from the official LLVM 23.1.1 macOS arm64 / Windows x64+arm64 releases) are the releases the Dockerfiles now install from; every checksum pin is updated. - Dockerfile.musl: Alpine 3.23 stops at LLVM 21 and LLVM 23 is in edge only, so clang23/llvm23/lld23 come from edge/main as a tagged repository. musl, libstdc++ and gcc stay 3.23's (container and aarch64 sysroot alike). The one package that follows clang from edge is libgcc-static; the sysroot step now also checks that clang selects the same GCC version for both. The unused clang/llvm -dev and -static packages are dropped (llvm23-dev would pull edge's python3). - lanes.mjs: the ARM64 CodeView register mapping that rules out an arm64 Windows lto lane is still missing in LLVM 23.1. --- .github/scripts/lanes.mjs | 2 +- .github/workflows/mirror-llvm-debs.yml | 2 +- Dockerfile | 6 ++--- Dockerfile.android | 6 ++--- Dockerfile.freebsd | 4 ++-- Dockerfile.macos | 10 ++++---- Dockerfile.musl | 33 ++++++++++++++++++-------- Dockerfile.windows | 28 +++++++++++----------- scripts/mirror-llvm-debs.sh | 2 +- 9 files changed, 53 insertions(+), 40 deletions(-) diff --git a/.github/scripts/lanes.mjs b/.github/scripts/lanes.mjs index 6820c5052aba9..8c2a308268b28 100644 --- a/.github/scripts/lanes.mjs +++ b/.github/scripts/lanes.mjs @@ -156,7 +156,7 @@ const platforms = [ // ASAN is x64 only: LLVM ships no Windows ARM64 ASAN runtime. The sanitizer runtime (import lib, /MT runtime // thunk, DLL) comes from the compiler-rt-windows-* release tag. amd64: ["release", "lto", "debug", "asan"], - // No arm64 lto: LLVM 21's CodeView emitter has no register mapping for ARM64 NEON quad-register tuples + // No arm64 lto: LLVM's CodeView emitter (still true of 23.1) has no register mapping for ARM64 NEON quad-register tuples // ("LLVM ERROR: unknown codeview register Q22_Q23_Q24_Q25") and the LTO codegen allocates values into them. arm64: ["release", "debug"], }, diff --git a/.github/workflows/mirror-llvm-debs.yml b/.github/workflows/mirror-llvm-debs.yml index 15f236a7eee95..73dad65464d1a 100644 --- a/.github/workflows/mirror-llvm-debs.yml +++ b/.github/workflows/mirror-llvm-debs.yml @@ -9,7 +9,7 @@ on: llvm_version: description: 'LLVM major version to mirror' type: string - default: '21' + default: '23' permissions: contents: write diff --git a/Dockerfile b/Dockerfile index 693a114c9a794..87d4f9950bad5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,7 @@ ARG MARCH_FLAG="" ARG WEBKIT_RELEASE_TYPE=Release ARG LTO_FLAG="-flto=thin -fno-split-lto-unit -fwhole-program-vtables -fforce-emit-vtables " ARG RELEASE_FLAGS="-O3 -DNDEBUG=1" -ARG LLVM_VERSION="21" +ARG LLVM_VERSION="23" # The -lto variants append -g1 (line tables only) after this, see $G below; every other variant keeps full -g. ARG DEFAULT_CFLAGS="-mno-omit-leaf-frame-pointer -g -fno-omit-frame-pointer -ffunction-sections -fdata-sections -faddrsig -fno-unwind-tables -fno-asynchronous-unwind-tables -DU_STATIC_IMPLEMENTATION=1 " ARG ENABLE_SANITIZERS="" @@ -105,8 +105,8 @@ RUN update-alternatives --install /usr/bin/gcc gcc /usr/bin/gcc-13 130 \ # GitHub release so the image doesn't depend on apt.llvm.org at build time. # Ubuntu-archive dependencies still come from apt. Regenerate via # scripts/mirror-llvm-debs.sh (or the mirror-llvm-debs workflow). -ARG LLVM_DEBS_SHA256_amd64=759ea9d6d50de9b6062cf40161a24a3a9d70aaf11aa1a544074d126590eb55f7 -ARG LLVM_DEBS_SHA256_arm64=4d4923baa663cb2e1be67e8e7097220604489b0da8b7a4ab5911ac2baf1e0ba6 +ARG LLVM_DEBS_SHA256_amd64=6a6abdf5237c8905c44423cb7ee25e687a2c9715b5133258f6dad65ff6e6bc53 +ARG LLVM_DEBS_SHA256_arm64=57e82d805bc3214fb7170715a01a5a207112fabbdef564c8153d89b10f9ff853 RUN curl -fsSL --retry 5 --retry-connrefused \ "https://github.com/oven-sh/WebKit/releases/download/llvm-${LLVM_VERSION}-debs/llvm-${LLVM_VERSION}-focal-amd64.tar.gz" \ -o /tmp/llvm.tar.gz \ diff --git a/Dockerfile.android b/Dockerfile.android index 1f770659264b8..fd9171870109c 100644 --- a/Dockerfile.android +++ b/Dockerfile.android @@ -1,8 +1,8 @@ ARG MARCH_FLAG="-march=armv8-a+crc -mtune=cortex-a78" ARG WEBKIT_RELEASE_TYPE=Release ARG LTO_FLAG="" -ARG LLVM_VERSION="21" -ARG LLVM_DEBS_SHA256="4a79b0eae89af72b082997d361198f16aaefce3fa8ad3c56c8e97311ff31dd5f" +ARG LLVM_VERSION="23" +ARG LLVM_DEBS_SHA256="993eba8b8ca23ea4d6074643d52ff9397b411e6ac5af6b7b2ca09dca2b351011" ARG NDK_VERSION="r27c" ARG NDK_SHA256="59c2f6dc96743b5daf5d1626684640b20a6bd2b1d85b13156b90333741bad5cc" ARG ANDROID_API="28" @@ -27,7 +27,7 @@ RUN apt-get update && apt-get install -y --no-install-recommends \ # Host clang (same version Bun uses) — we cross-compile via --target/--sysroot, # not via the NDK's bundled clang. apt.llvm.org installs version-suffixed names -# only (ld.lld-21, not ld.lld), so add unversioned links for -fuse-ld=lld. +# only (ld.lld-23, not ld.lld), so add unversioned links for -fuse-ld=lld. # The debs are mirrored from apt.llvm.org to a GitHub release (see # scripts/mirror-llvm-debs.sh) so the build doesn't depend on apt.llvm.org. ADD --checksum=sha256:${LLVM_DEBS_SHA256} \ diff --git a/Dockerfile.freebsd b/Dockerfile.freebsd index 5898c557c1700..6bfc81563965a 100644 --- a/Dockerfile.freebsd +++ b/Dockerfile.freebsd @@ -1,8 +1,8 @@ ARG MARCH_FLAG="-march=nehalem" ARG WEBKIT_RELEASE_TYPE=Release ARG LTO_FLAG="" -ARG LLVM_VERSION="21" -ARG LLVM_DEBS_SHA256="4a79b0eae89af72b082997d361198f16aaefce3fa8ad3c56c8e97311ff31dd5f" +ARG LLVM_VERSION="23" +ARG LLVM_DEBS_SHA256="993eba8b8ca23ea4d6074643d52ff9397b411e6ac5af6b7b2ca09dca2b351011" ARG FREEBSD_VERSION="14.3" ARG FREEBSD_ARCH="x86_64" ARG DEFAULT_CFLAGS="-mno-omit-leaf-frame-pointer -fno-omit-frame-pointer -ffunction-sections -fdata-sections -faddrsig -fno-unwind-tables -fno-asynchronous-unwind-tables -DU_STATIC_IMPLEMENTATION=1 " diff --git a/Dockerfile.macos b/Dockerfile.macos index 3c8e0c92b7fc5..b8285cb3744de 100644 --- a/Dockerfile.macos +++ b/Dockerfile.macos @@ -28,8 +28,8 @@ ARG BUN_DOWNLOAD_URL="https://pub-5e11e972747a44bf9aaf9394f185a982.r2.dev/releas ARG WEBKIT_RELEASE_TYPE=Release ARG LTO_FLAG="" ARG MARCH_FLAG="-mcpu=apple-m1" -ARG LLVM_VERSION="21" -ARG LLVM_DEBS_SHA256="4a79b0eae89af72b082997d361198f16aaefce3fa8ad3c56c8e97311ff31dd5f" +ARG LLVM_VERSION="23" +ARG LLVM_DEBS_SHA256="993eba8b8ca23ea4d6074643d52ff9397b411e6ac5af6b7b2ca09dca2b351011" ARG BOOTSTRAP_CMDS_TAG="bootstrap_cmds-138" # What every variant is compiled with. Cross-only additions live in the build stage. ARG DEFAULT_CFLAGS="-fno-exceptions -fvisibility=hidden -fvisibility-inlines-hidden -O3 -g -fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -faddrsig " @@ -46,8 +46,8 @@ ARG ENABLE_MALLOC_HEAP_BREAKDOWN="OFF" ARG ENABLE_SANITIZERS="" ARG USE_MIMALLOC="OFF" ARG USE_EXTERNAL_MIMALLOC="OFF" -ARG COMPILER_RT_DARWIN_TAG="compiler-rt-darwin-21.1.8" -ARG COMPILER_RT_DARWIN_SHA256="f9bab8191d63873682ec69492d06cfdf0807a7335c4e9b188ef013b3cc3c9dbc" +ARG COMPILER_RT_DARWIN_TAG="compiler-rt-darwin-23.1.1" +ARG COMPILER_RT_DARWIN_SHA256="35241a2d4cff6119b78279ace69cf89c9a190bd5ec7d2baa8d9d7f2a45d9957b" FROM ubuntu:24.04 AS base SHELL ["/bin/bash", "-o", "pipefail", "-c"] @@ -119,7 +119,7 @@ ENV MACOS_SDK=/opt/MacOSX${MACOS_SDK_VERSION}.sdk # in Dockerfile). Installed into clang's resource dir where the darwin # driver looks for libclang_rt.*_osx*. ADD --checksum=sha256:${COMPILER_RT_DARWIN_SHA256} \ - https://github.com/oven-sh/WebKit/releases/download/${COMPILER_RT_DARWIN_TAG}/compiler-rt-darwin-21.1.8-arm64.tar.gz /compiler-rt-darwin.tar.gz + https://github.com/oven-sh/WebKit/releases/download/${COMPILER_RT_DARWIN_TAG}/compiler-rt-darwin-23.1.1-arm64.tar.gz /compiler-rt-darwin.tar.gz RUN tar -xzf /compiler-rt-darwin.tar.gz -C /usr/lib/llvm-${LLVM_VERSION}/lib/clang/${LLVM_VERSION}/lib/ && \ rm /compiler-rt-darwin.tar.gz && \ test -f /usr/lib/llvm-${LLVM_VERSION}/lib/clang/${LLVM_VERSION}/lib/darwin/libclang_rt.asan_osx_dynamic.dylib diff --git a/Dockerfile.musl b/Dockerfile.musl index 2b72e53fa8124..ebc80602503e8 100644 --- a/Dockerfile.musl +++ b/Dockerfile.musl @@ -13,16 +13,23 @@ ARG LINUX_ARCH="x86_64" # Without that, it is built here like any other stage. Lane settings belong in `lane` below. FROM alpine:3.23 as base +# LLVM 23 is in Alpine edge only. `@edge` is a tagged repository: apk takes a package from it only when the package is +# asked for with that tag, or when a tagged package needs something 3.23 does not have. So musl, libstdc++ and gcc stay +# 3.23's, here and in the aarch64 sysroot below (which copies /etc/apk/repositories). The one thing that does follow +# clang from edge is libgcc-static (libgcc.a and the crt files of this container's architecture; 3.23 has no such +# package): the sysroot step checks that it is still the GCC version of the sysroot's. +# Edge is a rolling repository: a rebuild of this stage takes the 23.x that is there on that day. +RUN echo "@edge https://dl-cdn.alpinelinux.org/alpine/edge/main" >> /etc/apk/repositories RUN apk update -RUN apk add --no-cache cmake make clang21 clang21-static clang21-dev llvm21-dev llvm21-static musl-dev git lld libgcc gcc g++ libstdc++ build-base lld-dev llvm21-libs libc-dev xz zlib zlib-dev libxml2 libxml2-dev +RUN apk add --no-cache cmake make clang23@edge llvm23@edge lld23@edge musl-dev git libgcc gcc g++ libstdc++ build-base libc-dev xz zlib zlib-dev libxml2 libxml2-dev # What the ICU and WebKit stages need on top of that. RUN apk add --no-cache cpio curl tar nodejs patch file gnupg ninja ruby ruby-getoptlong unzip rsync perl python3 openssl-dev openssl linux-headers -ENV CXX=clang++-21 -ENV CC=clang-21 -ENV LDFLAGS='-L/usr/include -L/usr/include/llvm21' -ENV CXXFLAGS="-I/usr/include -I/usr/include/llvm21" -ENV PATH="/usr/bin:/usr/local/bin:/zig/bin:/usr/lib/llvm21/bin:$PATH" +ENV CXX=clang++-23 +ENV CC=clang-23 +ENV LDFLAGS='-L/usr/include -L/usr/include/llvm23' +ENV CXXFLAGS="-I/usr/include -I/usr/include/llvm23" +ENV PATH="/usr/bin:/usr/local/bin:/zig/bin:/usr/lib/llvm23/bin:$PATH" ENV WEBKIT_OUT_DIR=/webkitbuild RUN mkdir -p /output/lib /output/include /output/include/JavaScriptCore /output/include/wtf /output/include/bmalloc /output/include/unicode @@ -55,12 +62,13 @@ RUN curl -fsSL "https://github.com/facebook/zstd/releases/download/v${ZSTD_VERSI # /usr/include/fortify. This container has them as a dependency of clang; a sysroot has no clang, and without # them the define does nothing (musl has no fortify of its own) and the aarch64 lanes lose the checks the x86_64 ones have. # -# The clang configuration file: Alpine gives clang its default flags in /etc/clang21/.cfg, which clang reads for +# The clang configuration file: Alpine gives clang its default flags in /etc/clang23/.cfg, which clang reads for # the triple it compiles for. The clang package installs the container's own (-fstack-clash-protection); the aarch64 # package installs the same file under the aarch64 triple, and here nothing does, so it is copied: the aarch64 lanes # then get every default the x86_64 ones get, whatever Alpine puts there. # -# The musl and the fortify-headers an artifact is built against must be the container's own: checked here. +# The musl and the fortify-headers an artifact is built against must be the container's own, and its libgcc and crt +# files the same GCC version as the container's: checked here. # ─────────────────────────────────────────────────────────────────────────── ENV SYSROOT_AARCH64=/opt/sysroot-aarch64 RUN set -eu; \ @@ -78,9 +86,14 @@ RUN set -eu; \ echo "fortify-headers: container $container, aarch64 sysroot $sysroot"; \ [ -n "$container" ] || { echo "error: this container has no fortify-headers" >&2; exit 1; }; \ [ "$container" = "$sysroot" ] || { echo "error: the aarch64 sysroot's fortify-headers is not the container's" >&2; exit 1; }; \ + container=$(env -u CFLAGS -u CXXFLAGS -u LDFLAGS ${CC} -v 2>&1 | sed -n 's|^Selected GCC installation: .*/||p'); \ + sysroot=$(env -u CFLAGS -u CXXFLAGS -u LDFLAGS ${CC} --target=aarch64-alpine-linux-musl --sysroot="$SYSROOT_AARCH64" -v 2>&1 | sed -n 's|^Selected GCC installation: .*/||p'); \ + echo "GCC installation clang selects: container $container, aarch64 sysroot $sysroot"; \ + [ -n "$container" ] || { echo "error: clang selects no GCC installation in this container" >&2; exit 1; }; \ + [ "$container" = "$sysroot" ] || { echo "error: the aarch64 sysroot's GCC is not the version of the container's (libgcc-static from edge has moved on)" >&2; exit 1; }; \ test -f "$SYSROOT_AARCH64/usr/include/fortify/string.h"; \ - test -s /etc/clang21/x86_64-alpine-linux-musl.cfg; \ - cp /etc/clang21/x86_64-alpine-linux-musl.cfg /etc/clang21/aarch64-alpine-linux-musl.cfg; \ + test -s /etc/clang23/x86_64-alpine-linux-musl.cfg; \ + cp /etc/clang23/x86_64-alpine-linux-musl.cfg /etc/clang23/aarch64-alpine-linux-musl.cfg; \ test -f "$SYSROOT_AARCH64/usr/lib/libc.so"; \ test -f "$SYSROOT_AARCH64/usr/lib/libstdc++.a"; \ ls -d "$SYSROOT_AARCH64"/usr/lib/gcc/aarch64-alpine-linux-musl/*/crtbegin.o diff --git a/Dockerfile.windows b/Dockerfile.windows index a3968366a0406..2d2df0b75962a 100644 --- a/Dockerfile.windows +++ b/Dockerfile.windows @@ -33,8 +33,8 @@ ARG ICU_MARCH_FLAG="-march=nehalem" ARG ENABLE_SANITIZERS="" ARG USE_MIMALLOC="OFF" ARG USE_EXTERNAL_MIMALLOC="OFF" -ARG LLVM_VERSION="21" -ARG LLVM_DEBS_SHA256="4a79b0eae89af72b082997d361198f16aaefce3fa8ad3c56c8e97311ff31dd5f" +ARG LLVM_VERSION="23" +ARG LLVM_DEBS_SHA256="993eba8b8ca23ea4d6074643d52ff9397b411e6ac5af6b7b2ca09dca2b351011" ARG XWIN_VERSION="0.9.0" ARG XWIN_SHA256="31e1033f30608ba6b821d17f1461042bd54c23424813c9b4e9ae15b6d32fa4cd" # Pinned MSVC CRT + Windows SDK versions. Bump deliberately; the manifest on @@ -161,10 +161,10 @@ RUN set -e; \ # 2.0 with LLVM exceptions; redistribution is permitted. # OptionsMSVC.cmake's find_library(CLANG_BUILTINS_LIBRARY) searches # WebKitLibraries/windows, which is symlinked to /winsdk in the build stage. -ADD --checksum=sha256:9cff03d2c5218693b1f91efc0074957c710eeddd932d57a681c8f558b81fbe8e \ - https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-21.1.8/clang_rt.builtins-x86_64.lib /winsdk/clang_rt.builtins-x86_64.lib -ADD --checksum=sha256:b1bfec6276dde6166aa038de10c378ec17996779786fe1747c40b833cb826e16 \ - https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-21.1.8/clang_rt.builtins-aarch64.lib /winsdk/clang_rt.builtins-aarch64.lib +ADD --checksum=sha256:a4bd318f1337b876bfe97ac8a512708b586ad1a881d92e574233e19f8f25879c \ + https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-23.1.1/clang_rt.builtins-x86_64.lib /winsdk/clang_rt.builtins-x86_64.lib +ADD --checksum=sha256:b4105785d8b0f39bbcd958fd2fbafeb11b5441a0b85fe55b5cf51a48a520ca38 \ + https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-23.1.1/clang_rt.builtins-aarch64.lib /winsdk/clang_rt.builtins-aarch64.lib # Windows ASAN/UBSan runtime for the -asan variant, mirrored from the same # LLVM release as the builtins above (x64 only: LLVM ships no Windows ARM64 @@ -175,14 +175,14 @@ ADD --checksum=sha256:b1bfec6276dde6166aa038de10c378ec17996779786fe1747c40b833cb # UBSan handlers, so -fsanitize=address,undefined needs no separate # ubsan_standalone libraries. A Linux LLVM install doesn't ship any of these; # WebKitCompilerFlags.cmake locates them via CLANG_LIB_PATH (set below). -ADD --checksum=sha256:3dff47943143ab2c1a786a7c90c88f897bfa34e8b5a4c9382eadf8373fd19ec0 \ - https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-21.1.8/clang_rt.asan_dynamic-x86_64.lib /winsdk/clang_rt.asan_dynamic-x86_64.lib -ADD --checksum=sha256:d4a0398ed7d2e1361674fbb2cfceec4df502052cfe17b51718b061e9fe523719 \ - https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-21.1.8/clang_rt.asan_static_runtime_thunk-x86_64.lib /winsdk/clang_rt.asan_static_runtime_thunk-x86_64.lib -ADD --checksum=sha256:b3c1d6c988792651cc0b0b61b4114cbe513a5e2f6beb067fd54a96b98be9b328 \ - https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-21.1.8/clang_rt.asan_dynamic_runtime_thunk-x86_64.lib /winsdk/clang_rt.asan_dynamic_runtime_thunk-x86_64.lib -ADD --checksum=sha256:14025e779d3c67c53027312d7542aea8f814e5237e59f41cfc6165666189f886 \ - https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-21.1.8/clang_rt.asan_dynamic-x86_64.dll /winsdk/clang_rt.asan_dynamic-x86_64.dll +ADD --checksum=sha256:d7b1528432b69fe4fc924b29bf17729ec1eac1e2a9f6ff3384059ae71743d00c \ + https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-23.1.1/clang_rt.asan_dynamic-x86_64.lib /winsdk/clang_rt.asan_dynamic-x86_64.lib +ADD --checksum=sha256:2687c8aa22884f4defb160ad8368e715390c72f6b6f1f7f5d632a0cf37ab879d \ + https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-23.1.1/clang_rt.asan_static_runtime_thunk-x86_64.lib /winsdk/clang_rt.asan_static_runtime_thunk-x86_64.lib +ADD --checksum=sha256:bcd9f8c2c8041ba8e4ad0f3cb642bbf9a173d757fc864ffcc097da8661047379 \ + https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-23.1.1/clang_rt.asan_dynamic_runtime_thunk-x86_64.lib /winsdk/clang_rt.asan_dynamic_runtime_thunk-x86_64.lib +ADD --checksum=sha256:4fc14438122d1c397698099fcb0e1bdbca4af1a2524f3426c6815dcfaa639369 \ + https://github.com/oven-sh/WebKit/releases/download/compiler-rt-windows-23.1.1/clang_rt.asan_dynamic-x86_64.dll /winsdk/clang_rt.asan_dynamic-x86_64.dll # Sanity check: compile + link a PE executable for both arches. RUN for pair in "x86_64 x64" "aarch64 arm64"; do \ diff --git a/scripts/mirror-llvm-debs.sh b/scripts/mirror-llvm-debs.sh index 6be3e766f5ec3..d5c41dc8fc828 100755 --- a/scripts/mirror-llvm-debs.sh +++ b/scripts/mirror-llvm-debs.sh @@ -16,7 +16,7 @@ set -euo pipefail REPO="${REPO:-oven-sh/WebKit}" -LLVM_VERSION="${LLVM_VERSION:-21}" +LLVM_VERSION="${LLVM_VERSION:-23}" TAG="${TAG:-llvm-${LLVM_VERSION}-debs}" OUT="${OUT:-/tmp/llvm-debs}" V="$LLVM_VERSION" From 0f8be41164cf291fea1c6475e4dba5bae366b2c8 Mon Sep 17 00:00:00 2001 From: Jarred Sumner Date: Wed, 16 Sep 2026 01:40:35 +0000 Subject: [PATCH 2/3] Dockerfile.freebsd: fall back to archive.freebsd.org for the sysroot FreeBSD 14.3 is EOL and download.freebsd.org/releases no longer serves its base.txz (404); it now lives under archive.freebsd.org/old-releases. The cached toolchain image hid this until the LLVM bump changed the image hash and the base stage had to be rebuilt. Try the live mirror first, then the archive, so a supported release and an archived one both resolve. --- Dockerfile.freebsd | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/Dockerfile.freebsd b/Dockerfile.freebsd index 6bfc81563965a..2aa7769bba214 100644 --- a/Dockerfile.freebsd +++ b/Dockerfile.freebsd @@ -56,7 +56,8 @@ RUN set -eux; \ *) echo "unsupported FREEBSD_ARCH ${FREEBSD_ARCH}" >&2; exit 1 ;; \ esac; \ mkdir -p /opt/freebsd-sysroot; \ - wget -q "https://download.freebsd.org/releases/${FBSD_DL_ARCH}/${FREEBSD_VERSION}-RELEASE/base.txz" -O /tmp/base.txz; \ + wget -q "https://download.freebsd.org/releases/${FBSD_DL_ARCH}/${FREEBSD_VERSION}-RELEASE/base.txz" -O /tmp/base.txz || \ + wget -q "https://archive.freebsd.org/old-releases/${FBSD_DL_ARCH}/${FREEBSD_VERSION}-RELEASE/base.txz" -O /tmp/base.txz; \ tar -C /opt/freebsd-sysroot -xJf /tmp/base.txz ./usr/include ./usr/lib ./lib; \ rm /tmp/base.txz ENV FREEBSD_SYSROOT=/opt/freebsd-sysroot From 74c8ee58741d35b5f5d7337fecf4e951c048fd02 Mon Sep 17 00:00:00 2001 From: Jarred Sumner Date: Wed, 16 Sep 2026 03:08:14 +0000 Subject: [PATCH 3/3] JSTests: bound ftl-osr-exit-materialize-phantom-array-with-live-butterfly by catches too The test recurses until --maxPerThreadStackUsage stops it and quits once check() has been entered 10000 times. Near the limit the call to check() itself overflows, so that count stalls while every level still runs its 1024 * 16 retries; how many such levels there are depends on native frame sizes, and each one multiplies the run time by ~16000. Same JSC commit, arm64 jsc under qemu, time to exit by stack limit: clang 21 build: hangs at 1540000 and 1640000, ~10 s elsewhere clang 23 build: hangs at 1500000, 1572864 (the harness default) and 1600000, ~10 s elsewhere Both finish from 1700000 up. So the LLVM 23 toolchain did not miscompile anything; its frame sizes land on the bad side of the default limit, and the test hit the 300 s hard timeout on the arm64 lto lane twice in a row. The catch block runs whether check() threw or could not be called, so it counts as well and quits at 50000. Configurations that were fine still end on the original counter (total=10001, caught=10915); the others end on the new one with ~8500 real check() calls, in under a minute even emulated. --- ...sr-exit-materialize-phantom-array-with-live-butterfly.js | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/JSTests/stress/ftl-osr-exit-materialize-phantom-array-with-live-butterfly.js b/JSTests/stress/ftl-osr-exit-materialize-phantom-array-with-live-butterfly.js index aceb48a33f535..c5b2e0618873d 100644 --- a/JSTests/stress/ftl-osr-exit-materialize-phantom-array-with-live-butterfly.js +++ b/JSTests/stress/ftl-osr-exit-materialize-phantom-array-with-live-butterfly.js @@ -2,6 +2,10 @@ //@ runDefault("--forceEagerCompilation=1") let total = 0; +// Near the stack limit the call to check() itself overflows, so `total` stops advancing while every level still runs +// its 1024 * 16 retries: how many such levels there are depends on native frame sizes, and each one multiplies the run +// time by ~16000. The catch block runs either way, so it bounds the test too. +let caught = 0; function check(v3) { if (++total > 10000) quit(0); @@ -15,6 +19,8 @@ function main() { try { check(v3); } catch { + if (++caught > 50000) + quit(0); const x = (() => { const a = new Array(8); a[0] = {}, a[1] = {}, a[2] = {}, a[3] = {}, a[0] = {}, a[5] = {}, a[6] = {}, a[7] = {};