Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 27 additions & 6 deletions .github/workflows/build-wheels.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ jobs:
strategy:
fail-fast: false
matrix:
os: [ubuntu-latest, windows-latest, macos-14, macos-15-intel]
os: [ubuntu-latest, windows-latest, windows-11-arm, macos-14, macos-15-intel]

steps:
- name: Checkout code
Expand All @@ -34,20 +34,33 @@ jobs:
run: |
echo "MACOSX_DEPLOYMENT_TARGET=$(sw_vers -productVersion | cut -d '.' -f 1-2)" >> $GITHUB_ENV
# This does not work inside CIBW_BEFORE_ALL_MACOS; Without it, the wheel repair fails.

- name: Windows - Set up pkg-config and CMake
if: runner.os == 'windows'
- name: Windows - Install CMake & pkgconfig
if: runner.os == 'Windows'
shell: bash
run: |
choco install cmake --version=3.31.5 --allow-downgrade -y --no-progress
choco install -y --no-progress --stoponfirstfailure pkgconfiglite

- name: Windows - Set x86-64 PKG_CONFIG_PATH
if: runner.os == 'Windows' && runner.arch == 'X64'
shell: bash
run: |
echo "PKG_CONFIG_PATH=C:/mingw64/lib/pkgconfig" >> $GITHUB_ENV

- name: Windows ARM64 - Set up compilers and OpenBLAS
if: runner.os == 'Windows' && runner.arch == 'ARM64'
shell: pwsh
run: |
$VsVars = 'C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvarsarm64.bat'
cmd /c "`"$VsVars`" && set" > "$env:RUNNER_TEMP\vcvars.txt"
./cibw-scripts/setup_windows_arm64.ps1

- name: Build wheels
uses: pypa/cibuildwheel@v3.4.1
env:
# All cibuildwheel options are here (nothing "hidden" in pyproject.toml)
CIBW_SKIP: "*-win32 *i686 cp3??t-*"
CIBW_SKIP: "*-win32 *i686 cp3??t-* cp310-win_arm64"
CIBW_BUILD_FRONTEND: build
CIBW_BUILD_VERBOSITY: 3
CIBW_TEST_REQUIRES: pytest scipy
Expand All @@ -65,6 +78,14 @@ jobs:
pip install delvewheel
CIBW_REPAIR_WHEEL_COMMAND_WINDOWS: |
bash ./cibw-scripts/repair_wheel_command_windows.sh {wheel} {dest_dir}
CIBW_ENVIRONMENT_PASS_WINDOWS: >
CC
CXX
FC
AR
PKG_CONFIG_PATH
OPENBLAS_DIR
ODRPACK_WIN_ARM64

- name: Upload wheels
uses: actions/upload-artifact@v6
Expand Down Expand Up @@ -127,4 +148,4 @@ jobs:

# - uses: pypa/gh-action-pypi-publish@release/v1
# with:
# repository-url: https://test.pypi.org/legacy/
# repository-url: https://test.pypi.org/legacy/
12 changes: 12 additions & 0 deletions cibw-scripts/before_all_windows.sh
Original file line number Diff line number Diff line change
@@ -1,5 +1,17 @@
#!/bin/bash
set -xe

# ARM64: compilers (CC/CXX/FC) and OpenBLAS are already set up by
# cibw-scripts/setup_windows_arm64.ps1, so there is nothing to install here.
if [[ -n "${ODRPACK_WIN_ARM64:-}" ]]; then
clang-cl --version
flang-new --version
pkg-config --modversion openblas
exit 0
fi

# x86-64: install OpenBLAS via MSYS2/MinGW.

# Verify active compiler locations
which gcc
which gfortran
Expand Down
56 changes: 56 additions & 0 deletions cibw-scripts/setup_windows_arm64.ps1
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
$ErrorActionPreference = 'Stop'
$ProgressPreference = 'SilentlyContinue'
$LlvmVersion = '22.1.8'
$LlvmBin = 'C:\Program Files\LLVM\bin'
$LlvmInstaller = "$env:RUNNER_TEMP\LLVM-22.1.8-woa64.exe"
$LlvmUrl = "https://github.com/llvm/llvm-project/releases/download/llvmorg-$LlvmVersion/LLVM-$LlvmVersion-woa64.exe"
Invoke-WebRequest $LlvmUrl -UseBasicParsing -OutFile $LlvmInstaller

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No hash verification for downloaded binaries (High Risk).

  • Lines 7 and 28 download executables and archives without verifying checksums
  • An attacker performing a MITM attack or compromising GitHub's release infrastructure could inject malicious code
  • Fix: Validate SHA256 hashes against known good values

Start-Process -FilePath $LlvmInstaller -ArgumentList '/S' -Wait
$env:PATH = "$LlvmBin;$env:PATH"
$LlvmBin | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append
$LlvmRuntime = "$LlvmBin\..\lib\clang\22.1.8\lib\windows"
$FlangRuntime = "$LlvmBin\..\lib\clang\22\lib\aarch64-pc-windows-msvc"
$env:LIB = "$FlangRuntime;$LlvmRuntime;$env:LIB"
"LIB=$env:LIB" | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append
@(
'CC=clang-cl'
'CXX=clang-cl'
'FC=flang-new'
'AR=llvm-ar'
'ODRPACK_WIN_ARM64=1'
) | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append

$OpenBlasVersion = '0.3.34'
$OpenBlasDir = 'C:\openblas'
$zip = "$env:RUNNER_TEMP\openblas.zip"
$tmp = "$env:RUNNER_TEMP\openblas_extract"
$url = "https://github.com/OpenMathLib/OpenBLAS/releases/download/v$OpenBlasVersion/OpenBLAS-$OpenBlasVersion-woa64-64-dll.zip"
Invoke-WebRequest -Uri $url -OutFile $zip -UseBasicParsing

# Extract to a temp dir, then flatten the top-level OpenBLAS folder
Expand-Archive -LiteralPath $zip -DestinationPath $tmp -Force
Move-Item "$tmp\OpenBLAS" $OpenBlasDir

$pkgConfigDir = "$OpenBlasDir\lib\pkgconfig"
$prefix = $OpenBlasDir.Replace('\', '/')

@"
libdir=$prefix/lib
libnameprefix=
libnamesuffix=
libsuffix=
includedir=$prefix/include/openblas

Name: OpenBLAS
Description: OpenBLAS is an optimized BLAS library based on GotoBLAS2 1.13 BSD version
Version: $OpenBlasVersion
URL: https://github.com/OpenMathLib/OpenBLAS
Libs: -L`${libdir} -l`${libnameprefix}openblas`${libnamesuffix}`${libsuffix}
Cflags: -I`${includedir}
"@ | Set-Content -LiteralPath "$pkgConfigDir\openblas.pc" -Encoding ASCII
@(
"PKG_CONFIG_PATH=$($pkgConfigDir.Replace('\', '/'))"
"OPENBLAS_DIR=$OpenBlasDir"
) | Out-File -FilePath $env:GITHUB_ENV -Encoding utf8 -Append

"$OpenBlasDir\bin" | Out-File -FilePath $env:GITHUB_PATH -Encoding utf8 -Append