Skip to content

chore(deps): bump aws-lc - #2082

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 2 commits into
mainfrom
thieman/bump-aws-lc-aix
Jul 10, 2026
Merged

chore(deps): bump aws-lc#2082
gh-worker-dd-mergequeue-cf854d[bot] merged 2 commits into
mainfrom
thieman/bump-aws-lc-aix

Conversation

@thieman

@thieman thieman commented Jul 10, 2026

Copy link
Copy Markdown
Contributor

Summary

Bump aws-lc-rs to 1.17.1, which updates aws-lc-sys to 0.42.0.

aws-lc-sys 0.42.0 includes upstream AWS-LC changes from aws/aws-lc#3265 that guard Linux-only entropy code when compiling on AIX.

Validation

  • cargo check -p saluki-tls
  • Pre-commit hook:
    • make fmt checks
    • cargo clippy --all-targets --workspace -- -D warnings
    • license check
    • cargo deny check --hide-inclusion-graph --show-stats (existing source warning only)
    • docs check
    • API docs generation

thieman added 2 commits July 10, 2026 15:38
Bump aws-lc-rs to 1.17.1, which updates aws-lc-sys to 0.42.0. The newer aws-lc-sys includes upstream AIX compile fixes for Linux-only entropy code guards.
Restore the workspace aws-lc-rs manifest requirement to version 1. The lockfile bump is sufficient to select aws-lc-rs 1.17.1 and aws-lc-sys 0.42.0 for this repository.
@thieman
thieman marked this pull request as ready for review July 10, 2026 19:42
@thieman
thieman requested a review from a team as a code owner July 10, 2026 19:42
@pr-commenter

pr-commenter Bot commented Jul 10, 2026

Copy link
Copy Markdown

Binary Size Analysis (Agent Data Plane)

Baseline: 5f214f2 · Comparison: 01b913a · diff
Analysis Configuration: stripped binaries · Pass/Fail Threshold: +5%
Sizes: 41.55 MiB (baseline) vs 41.58 MiB (comparison)
Size Change: +27.54 KiB (+0.06%)

✅ Binary size difference within threshold

Changes by Module
Module File Size Symbols
aws_lc_0_42_0_aes_gcm_encrypt_avx512 +333.79 KiB 1
aws_lc_0_41_0_aes_gcm_decrypt_avx512 -333.79 KiB 1
aws_lc_0_41_0_aes_gcm_encrypt_avx512 -332.11 KiB 1
aws_lc_0_42_0_aes_gcm_decrypt_avx512 +332.10 KiB 1
aws_lc_0_42_0_edwards25519_scalarmulbase_alt +60.33 KiB 1
aws_lc_0_41_0_edwards25519_scalarmulbase_alt -60.33 KiB 1
aws_lc_0_42_0_edwards25519_scalarmulbase +60.06 KiB 1
aws_lc_0_41_0_edwards25519_scalarmulbase -60.06 KiB 1
aws_lc_0_42_0_curve25519_x25519base_alt +59.86 KiB 1
aws_lc_0_41_0_curve25519_x25519base_alt -59.86 KiB 1
aws_lc_0_42_0_curve25519_x25519base +59.62 KiB 1
aws_lc_0_41_0_curve25519_x25519base -59.62 KiB 1
aws_lc_0_42_0_curve25519_x25519_byte_alt +21.68 KiB 1
aws_lc_0_41_0_curve25519_x25519_byte_alt -21.68 KiB 1
anon.72c3353df52191b74612acde54b2ebe7.240.llvm.4152876991496683762 +21.15 KiB 1
anon.906046189c51c143e7c52e4ee69c5016.30.llvm.13653499532151601150 -21.15 KiB 1
aws_lc_0_42_0_curve25519_x25519_byte +20.82 KiB 1
aws_lc_0_41_0_curve25519_x25519_byte -20.82 KiB 1
anon.7982b035c2501c8c015ba477222e7e44.7.llvm.16557284064573298568 +17.80 KiB 1
anon.6f071ebf99a89e7394ee542047fb4d79.8.llvm.3673436743351048125 -17.78 KiB 1
Detailed Symbol Changes
    FILE SIZE        VM SIZE    
 --------------  -------------- 
  [NEW]  +333Ki  [NEW]  +333Ki    aws_lc_0_42_0_aes_gcm_encrypt_avx512
  [NEW]  +332Ki  [NEW]  +332Ki    aws_lc_0_42_0_aes_gcm_decrypt_avx512
  [NEW] +60.3Ki  [NEW] +59.9Ki    aws_lc_0_42_0_edwards25519_scalarmulbase_alt
  [NEW] +60.1Ki  [NEW] +59.6Ki    aws_lc_0_42_0_edwards25519_scalarmulbase
  [NEW] +59.9Ki  [NEW] +59.4Ki    aws_lc_0_42_0_curve25519_x25519base_alt
  [NEW] +59.6Ki  [NEW] +59.1Ki    aws_lc_0_42_0_curve25519_x25519base
  [NEW] +56.3Ki  [NEW] +56.2Ki    saluki_components::common::datadog::io::run_endpoint_io_loop::_{{closure}}::h49375b69dcfb6f02
  [NEW] +41.5Ki  [NEW] +41.4Ki    agent_data_plane::cli::run::handle_run_command::_{{closure}}::h82b0f5413542bf87
  [NEW] +38.4Ki  [NEW] +38.2Ki    _<saluki_components::forwarders::otlp::OtlpForwarder as saluki_core::components::forwarders::Forwarder>::run::_{{closure}}::hadf9b85f315763cf
  [NEW] +30.6Ki  [NEW] +30.4Ki    _<saluki_components::transforms::aggregate::Aggregate as saluki_core::components::transforms::Transform>::run::_{{closure}}::hc9062a2a4246a7d4
  +0.1% +27.9Ki  +0.2% +26.9Ki    [52835 Others]
  [DEL] -30.6Ki  [DEL] -30.4Ki    _<saluki_components::transforms::aggregate::Aggregate as saluki_core::components::transforms::Transform>::run::_{{closure}}::h5c1589ffecbc9667
  [DEL] -38.4Ki  [DEL] -38.2Ki    _<saluki_components::forwarders::otlp::OtlpForwarder as saluki_core::components::forwarders::Forwarder>::run::_{{closure}}::h562fea205415e8e6
  [DEL] -41.5Ki  [DEL] -41.4Ki    agent_data_plane::cli::run::handle_run_command::_{{closure}}::h244a74d1ea5c869f
  [DEL] -56.7Ki  [DEL] -56.5Ki    saluki_components::common::datadog::io::run_endpoint_io_loop::_{{closure}}::h75350cf7be52522b
  [DEL] -59.6Ki  [DEL] -59.1Ki    aws_lc_0_41_0_curve25519_x25519base
  [DEL] -59.9Ki  [DEL] -59.4Ki    aws_lc_0_41_0_curve25519_x25519base_alt
  [DEL] -60.1Ki  [DEL] -59.6Ki    aws_lc_0_41_0_edwards25519_scalarmulbase
  [DEL] -60.3Ki  [DEL] -59.9Ki    aws_lc_0_41_0_edwards25519_scalarmulbase_alt
  [DEL]  -332Ki  [DEL]  -332Ki    aws_lc_0_41_0_aes_gcm_encrypt_avx512
  [DEL]  -333Ki  [DEL]  -333Ki    aws_lc_0_41_0_aes_gcm_decrypt_avx512
  +0.1% +27.5Ki  +0.1% +26.6Ki    TOTAL

@pr-commenter

pr-commenter Bot commented Jul 10, 2026

Copy link
Copy Markdown

Regression Detector (Agent Data Plane)

Run ID: c621e647-289f-48c4-893f-1cf66f250924
Baseline: 5f214f26 · Comparison: 01b913a6 · diff

Optimization Goals: ✅ No significant changes detected

Fine details of change detection per experiment (5)

Experiments configured erratic: true are tagged (ignored) and skipped when determining which experiments regressed or improved. Experiments which are detected as erratic at runtime are tagged (erratic) to flag that the run's sample dispersion was high, but their regression / improvement signal still counts.

experiment goal Δ mean % links
quality_gates_rss_dsd_low memory ⚪ +0.52 metrics profiles logs
quality_gates_rss_idle memory ⚪ +0.30 metrics profiles logs
quality_gates_rss_dsd_heavy memory ⚪ +0.15 metrics profiles logs
quality_gates_rss_dsd_medium memory ⚪ +0.12 metrics profiles logs
quality_gates_rss_dsd_ultraheavy memory ⚪ +0.03 metrics profiles logs
Bounds Checks: ✅ Passed (5)
experiment check replicates observed links
quality_gates_rss_dsd_heavy memory_usage 10/10 ✅ 131 MiB ≤ 140 MiB metrics profiles logs
quality_gates_rss_dsd_low memory_usage 10/10 ✅ 43.1 MiB ≤ 50 MiB metrics profiles logs
quality_gates_rss_dsd_medium memory_usage 10/10 ✅ 66.2 MiB ≤ 75 MiB metrics profiles logs
quality_gates_rss_dsd_ultraheavy memory_usage 10/10 ✅ 192 MiB ≤ 200 MiB metrics profiles logs
quality_gates_rss_idle memory_usage 10/10 ✅ 28.9 MiB ≤ 40 MiB metrics profiles logs
Explanation

A change is flagged as a regression when |Δ mean %| > 5.00% in the regressing direction for its optimization goal AND SMP marks the experiment as a regression (is_regression: true). Improvements use the matching criteria for the improving direction. Experiments configured erratic: true (tagged (ignored)) are skipped outright; experiments detected as erratic at runtime (tagged (erratic)) still count, since that flag describes sample dispersion rather than directional certainty. The Δ mean % cell is colored accordingly: 🟢 = improvement, 🔴 = regression, ⚪ = neutral. Reduction in CPU or memory is an improvement; reduction in ingress throughput is a regression.

@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot merged commit 0442baf into main Jul 10, 2026
84 checks passed
@gh-worker-dd-mergequeue-cf854d
gh-worker-dd-mergequeue-cf854d Bot deleted the thieman/bump-aws-lc-aix branch July 10, 2026 20:13
gh-worker-dd-mergequeue-cf854d Bot pushed a commit that referenced this pull request Jul 13, 2026
## Human Summary

Adds a script and Makefile target to build a release ADP binary on AIX. This comes with two intentional divergences from how we build on the other platforms:

- We can't use `cargo auditable` because it does not support XCOFF. Clanker tried to get it to work with some manual patching but wasn't able to. Seems like this will be a more significant contribution to upstream if we want this to work.
- We can't use link-time optimization (LTO) because it doesn't seem to work on AIX at all, even for a hello-world crate. This is actually called out in IBM's docs [here](https://www.ibm.com/docs/en/osfroa/1.90.0?topic=started-introducing-rustc-compiler).

Neither of these should be showstoppers, but please comment if they are. The plan will be to call this script from within the Agent's `packaging/aix` machinery when we do AIX builds. Working on that follow-up now.

## Summary

- Adds `make build-adp-aix` for native AIX ADP builds using the IBM Rust SDK and AIX Toolbox GCC toolchain.
- Adds `ci/tooling/build-adp-aix.sh` to record the AIX build environment and run the native Cargo build.
- Adds an `aix-optimized-release` Cargo profile that keeps the optimized-release binary settings that work on AIX while disabling LTO.
- Checks the major toolchain versions for cargo/rustc/gcc/g++ so AIX builds fail loudly if the toolchain drifts unexpectedly.

## Notes

- The AIX enablement and AWS-LC dependency changes from #2031, #2032, #2034, #2060, and #2082 are now on `main`; this PR is rebased on top of them and only carries the build helper/profile changes.
- `aws-lc-sys` is built from the bumped dependency without patching Cargo's registry cache.
- On the AIX test host, `gcc-8` fails in an AWS-LC compiler feature probe; `/opt/freeware/bin/gcc` (`gcc 13.3`) succeeds, so the helper defaults to that compiler.
- AIX currently does not use `cargo auditable`: cargo-auditable emits ELF/generic Unix linker inputs and flags that AIX's XCOFF linker rejects.
- AIX currently uses `aix-optimized-release` instead of `optimized-release`: the IBM Rust SDK 1.92 fails LTO even for a tiny hello-world crate with `failed to get bitcode from object file for LTO (Can't find section .ipa)`.
- The helper still uses the same metadata inputs that affect the ADP binary (`APP_FULL_NAME`, `APP_SHORT_NAME`, `APP_IDENTIFIER`, `APP_VERSION`, `APP_GIT_HASH`, `APP_BUILD_TIME`, `APP_DEV_BUILD`) and passes `BUILD_FEATURES` through to Cargo.
- Toolchain version prefixes are overrideable through `ADP_AIX_EXPECTED_*_PREFIX` variables when an intentional toolchain update occurs.

## Test Plan

- [x] `bash -n ci/tooling/build-adp-aix.sh`
- [x] `ADP_AIX_BUILD_DRY_RUN=true make build-adp-aix`
- [x] `cargo metadata --no-deps --format-version 1`
- [x] AIX: `CARGO_HOME=/opt/cargo-home-aix-adp-pr-stack CARGO_TARGET_DIR=/opt/saluki-aix-adp-pr-stack-target make build-adp-aix`
- [x] AIX: `/opt/saluki-aix-adp-pr-stack-target/aix-optimized-release/agent-data-plane --help`
- [x] AIX: `/opt/saluki-aix-adp-pr-stack-target/aix-optimized-release/agent-data-plane version`
- [x] Pre-commit hook: `fmt`, `check-clippy`, `check-licenses`, `check-deny`, `check-docs`, `generate-api-docs`

AIX toolchain observed:

- `cargo 1.92.0 (IBM Open SDK for Rust on AIX 1.92.0.0)`
- `rustc 1.92.0 (IBM Open SDK for Rust on AIX 1.92.0.0)`
- `gcc (GCC) 13.3.0`
- `g++ (GCC) 13.3.0`

AIX build result:

- `Finished aix-optimized-release profile [optimized + debuginfo] target(s) in 26m 22s`
- Binary: `64-bit XCOFF executable or object module not stripped`


Co-authored-by: travis.thieman <travis.thieman@datadoghq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants