From c78abf2de431f5db63ae69d811e9a0ff2d02cbd4 Mon Sep 17 00:00:00 2001 From: Myoungho Shin Date: Wed, 30 Sep 2026 08:27:35 -0700 Subject: [PATCH] Use the runner's OpenSSL for Windows release wheels The release job installed OpenSSL with `choco install openssl`, whose installer download from slproweb.com fails on GitHub-hosted runners, so the Windows wheels for v1.3.0rc3 never built. The windows-2022 image already installs the full OpenSSL 3.x (headers and import libraries) at C:\Program Files\OpenSSL, so point OPENSSL_ROOT_DIR and delvewheel's --add-path there and log its version before the build. find_package(OpenSSL) is QUIET, so a missing OpenSSL used to produce an HTTP-only wheel without complaint. CMAKE_REQUIRE_FIND_PACKAGE_OpenSSL makes it a configure error for the Windows release build. --- .github/workflows/release.yml | 30 ++++++++++++++++-------------- 1 file changed, 16 insertions(+), 14 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 6a898c5..95b6362 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -154,13 +154,15 @@ jobs: # Windows build needs the OpenSSL install path so find_package(OpenSSL) # in CMakeLists.txt succeeds, otherwise HTTPS upload (gpufl::uploadLogs) # silently falls back to HTTP-only - see openssl-windows.html in the - # manual repo for the user-facing story. CIBW_BEFORE_ALL_WINDOWS - # installs choco's openssl package into this path. + # manual repo for the user-facing story. The windows-2022 runner image + # preinstalls the full OpenSSL 3.x (headers + import libs) at this + # path. CMAKE_REQUIRE_FIND_PACKAGE_OpenSSL turns the QUIET lookup into + # a hard error, so a missing OpenSSL fails the build instead. CIBW_ENVIRONMENT_WINDOWS: >- - OPENSSL_ROOT_DIR="C:/Program Files/OpenSSL-Win64" + OPENSSL_ROOT_DIR="C:/Program Files/OpenSSL" CMAKE_GENERATOR="Visual Studio 17 2022" CMAKE_GENERATOR_PLATFORM="x64" - CMAKE_ARGS="-DGPUFL_ENABLE_NVIDIA=ON -DGPUFL_ENABLE_AMD=OFF -DBUILD_TESTING=OFF" + CMAKE_ARGS="-DGPUFL_ENABLE_NVIDIA=ON -DGPUFL_ENABLE_AMD=OFF -DBUILD_TESTING=OFF -DCMAKE_REQUIRE_FIND_PACKAGE_OpenSSL=ON" # cuda-nvml-devel-13-1 ships the libnvidia-ml.so stub under # targets/x86_64-linux/lib/stubs/ - without it CMake's NVML probe # finds nothing and (since v0.1.1) fails the build loudly. Every @@ -178,13 +180,13 @@ jobs: CIBW_BEFORE_ALL_LINUX: >- curl -fsSL https://developer.download.nvidia.com/compute/cuda/repos/rhel8/x86_64/cuda-rhel8.repo > /etc/yum.repos.d/cuda.repo && dnf install -y --nogpgcheck cuda-nvcc-13-1 cuda-cudart-devel-13-1 cuda-cupti-13-1 cuda-driver-devel-13-1 cuda-nvml-devel-13-1 openssl3-devel - # Install OpenSSL on the Windows runner so find_package(OpenSSL) - # in CMakeLists.txt succeeds and cpp-httplib gets compiled with - # CPPHTTPLIB_OPENSSL_SUPPORT=1. Chocolatey is pre-installed on - # GitHub's windows-latest runners; the openssl package installs - # to C:\Program Files\OpenSSL-Win64\ (matches OPENSSL_ROOT_DIR - # in CIBW_ENVIRONMENT_WINDOWS above). - CIBW_BEFORE_ALL_WINDOWS: choco install -y openssl --no-progress + # Use the OpenSSL the windows-2022 image already installs at + # C:\Program Files\OpenSSL (actions/runner-images Install-OpenSSL.ps1) + # rather than `choco install openssl`, whose installer download from + # slproweb.com fails on GitHub-hosted runners. This logs the version + # being bundled and fails fast if the install is missing. + CIBW_BEFORE_ALL_WINDOWS: >- + "C:\Program Files\OpenSSL\bin\openssl.exe" version # cibuildwheel ships NO default Windows repair command and only # auto-installs delvewheel for that (nonexistent) default. Because # we override CIBW_REPAIR_WHEEL_COMMAND_WINDOWS below (to pass @@ -219,13 +221,13 @@ jobs: # On Windows, cibuildwheel's default is `delvewheel repair`. # We need delvewheel to find the OpenSSL DLLs (libssl-3-x64.dll, # libcrypto-3-x64.dll) so it copies them into the wheel. The - # choco install puts them under C:\Program Files\OpenSSL-Win64\bin\ + # runner image keeps them under C:\Program Files\OpenSSL\bin\ # - give that to delvewheel via --add-path. Without this, the # rebuilt wheel imports cleanly on a system that already has # OpenSSL on PATH but fails on a clean machine. # delvewheel vendors the wheel's DLL deps. We must: # * --add-path the dirs holding the DLLs to bundle. OpenSSL is in - # its choco bin; cudart64_*.dll is in CUDA\vX.Y\bin (on PATH, but + # its bin; cudart64_*.dll is in CUDA\vX.Y\bin (on PATH, but # listed for safety); cupti64_*.dll lives in CUDA's # extras\CUPTI\lib64, which is NOT on PATH - without it delvewheel # fails with "Unable to find library: cupti64_2025.4.0.dll". We @@ -241,7 +243,7 @@ jobs: # step). Both --add-path and --exclude are ';'-delimited. CIBW_REPAIR_WHEEL_COMMAND_WINDOWS: >- delvewheel repair - --add-path "C:\\Program Files\\OpenSSL-Win64\\bin;C:\\Program Files\\NVIDIA GPU Computing Toolkit\\CUDA\\v13.1\\bin;C:\\Program Files\\NVIDIA GPU Computing Toolkit\\CUDA\\v13.1\\extras\\CUPTI\\lib64" + --add-path "C:\\Program Files\\OpenSSL\\bin;C:\\Program Files\\NVIDIA GPU Computing Toolkit\\CUDA\\v13.1\\bin;C:\\Program Files\\NVIDIA GPU Computing Toolkit\\CUDA\\v13.1\\extras\\CUPTI\\lib64" --exclude "nvcuda.dll;nvml.dll" -w {dest_dir} {wheel}