Trim the debian, rhel, fedora and alpine runner images - #793
Merged
Merged
Conversation
Apply the same trimming as the ubuntu images (#791, #792) to the other runners: - Keep only llvm-profdata and llvm-cov from llvm-tools-preview, symlink its duplicate libLLVM.so to rustc's copy, strip the big toolchain binaries with llvm-strip, and drop rust-std's sanitizer runtimes and wasm-component-ld. rhel and fedora compare the libraries with sha256sum since their base images have no cmp. - debian: gcc + libc6-dev instead of build-essential, --no-install-recommends (ca-certificates listed explicitly), and dpkg path-excludes for the static libpython/OpenSSL, gcc's LTO backend and the sanitizer runtimes. - rhel: git-core instead of git (drops perl and git-core-doc), no weak deps, no docs, and gcc's lto1/lto-dump removed. - fedora: git-core, no weak deps (python-unversioned-command kept explicitly), lto1/lto-dump removed, and ~/.cargo/bin/rustup made a symlink to the packaged rustup-init instead of a copy. - alpine: the 100MB static libpython, lto1/lto-dump and the sanitizer archives removed; on musl the llvm tools are statically linked so the toolchain trim saves ~750MB, and rust-lld is dropped as rustc uses the system linker there. Measured on x86_64 (uncompressed / zstd): bookworm 2.12GB / 538MB -> 1.39GB / 369MB alpine 2.49GB / 652MB -> 1.03GB / 267MB stream9 1.76GB / 450MB -> 1.16GB / 307MB fedora 1.91GB / 493MB -> 1.32GB / 351MB Verified by running cryptography's distros/alpine CI steps (nox "tests" session, with OPENSSL_ENABLE_SHA1_SIGNATURES=1 as ci.yml sets it) in the bookworm, alpine, centos-stream9, centos-stream10 and fedora images: all pass with the lcov file written by llvm-profdata/llvm-cov. trixie, sid and both FIPS variants build; all images pass from-source cffi/coverage builds, git clone/fetch/checkout, cargo test with doctests and a standalone -Cinstrument-coverage build. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LAX1TTcE6SPuzzGvGh4jdX
alex
approved these changes
Sep 18, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Applies the trimming from #791 and #792 to the other runner images.
Measured on x86_64:
trixie is 1.40 GB / 368 MB and sid 1.72 GB / 468 MB after (no baselines measured); sid's extra is Debian's gcc-16, whose
cc1is 240 MB vs 33 MB for gcc-14. centos-stream10 and the FIPS variants are 1.16–1.18 GB.Everywhere, as in #792: keep only
llvm-profdataandllvm-covfromllvm-tools-preview, symlink its duplicatelibLLVM.soto rustc's, strip the big toolchain binaries withllvm-strip(before it is deleted), and drop rust-std's sanitizer runtimes andwasm-component-ld. rhel and fedora compare the libraries withsha256sumsince their base images have nocmp.Per image:
gcc+libc6-devinstead ofbuild-essential,--no-install-recommends(ca-certificateslisted explicitly), and dpkg path-excludes for the static libpython/OpenSSL, gcc's LTO backend and the sanitizer runtimes.git-coreinstead ofgit(drops git-core-doc and ~60 perl packages),install_weak_deps=False,tsflags=nodocs, and gcc'slto1/lto-dumpremoved. The ubi8 branches are untouched.git-core,install_weak_deps=False(withpython-unversioned-commandkept explicitly since it was only a weak dep),lto1/lto-dumpremoved, and~/.cargo/bin/rustupmade a symlink to the packagedrustup-initinstead of a 9 MB copy.lto1/lto-dumpand the gcc sanitizer archives, andrust-lld, since rustc uses the system linker on musl (verified with--print link-args).Verification:
distros/alpinejob steps from cryptography'sci.yml(vector fetch,pip install nox[uv],nox --install-only, thetestssession, withOPENSSL_ENABLE_SHA1_SIGNATURES=1as ci.yml sets it) in the new bookworm, alpine, centos-stream9, centos-stream10 and fedora images: all pass (4193–4647 passed depending on the OpenSSL), withllvm-profdata/llvm-covwriting the lcov file at 93.8–96.9% Rust line coverage.cargo testincluding doctests passes, and a standalone-Cinstrument-coveragebuild goes throughllvm-profdataandllvm-cov. The FIPS images show the FIPS policy active.testssession in the alpine and ubuntu arm images; it needs nothing removed here.Not changed: alpine's
make(tiny, and I couldn't establish why it was added), Fedora's 59 MB of locale data (it's in the base image), and the aarch64 alpine variant couldn't be built locally, though the toolchain shell is the same host-agnostic logic that already passed CI on the ubuntu aarch64/armv7l/ppc64le builds.🤖 Generated with Claude Code
https://claude.ai/code/session_01LAX1TTcE6SPuzzGvGh4jdX
Generated by Claude Code