chore(deps): update delivery-kit and remove legacy ELF libraries - #493
Merged
Merged
Conversation
Use the current Delivery Kit 2 release and its delivery-kit-sdk v1.4.2 dependency, which implements ELF signing without the former OpenSSL static-link flags. Update the module graph and checksums. Signed-off-by: Aleksei Igrychev <aleksei.igrychev@palark.com>
Remove the system ELF, OpenSSL, libuv, zstd and zlib development packages used by the former SDK signer, together with its static-link workaround. Keep libbtrfs development headers for the remaining Buildah CGO code. Signed-off-by: Aleksei Igrychev <aleksei.igrychev@palark.com>
Contributor
Author
Verification
Review focus
Follow-up
Rollout progress
|
…ps/delivery-kit-2-79-1
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Update the embedded Delivery Kit to remove the ELF signer's C-library dependencies from d8 builds. The previous SDK prevents static linking on Ubuntu 26.04 with OpenSSL 3.5, reporting unresolved
jent_read_entropyanduncompresssymbols.What
v2.69.0-dktov2.79.1-dk.1, including its required SDK, nelm, kubedog, logboek and copy-recurse versions.v1.4.2, whose ELF signer uses Go andelfeditinstead of the former C implementation. VERIFIED: the minimal signer program links statically and runs on Ubuntu 26.04.1 where SDKv1.2.0fails.libelf-dev,libssl-dev,libuv1-dev,libzstd-devandzlib1g-devin the release build, and remove theCGO_LDFLAGS=-lzworkaround.libbtrfs-devfor Buildah and the existing static-linking flags in Taskfile; this does not remove CGO from d8 as a whole.Why
The old SDK hardcodes a static C-library link list. Ubuntu 26.04's OpenSSL 3.5 needs additional transitive dependencies and exposes the incorrect zlib ordering in that list, so importing the SDK can break the entire d8 build even when ELF signing is not used.
Updating to the Go implementation removes that dependency on the host's OpenSSL link requirements. Maintaining another linker workaround in d8 would leave the same distribution-dependent failure mode in place; the release build's former signer packages and
-lzworkaround are no longer needed.