From e922eb4be479d322011b5f00ecd88b446d524a68 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 11 Sep 2026 12:33:18 +0000 Subject: [PATCH 1/3] Switch downstream tests to Ubuntu 26.04 Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01EkX3LD8jYgtCyGDVRUq6cr --- .github/workflows/ci.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 64782604f02d..6d87408ac453 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -368,7 +368,7 @@ jobs: - uses: ./.github/actions/upload-coverage linux-downstream: - runs-on: ubuntu-latest + runs-on: ubuntu-26.04 strategy: fail-fast: false matrix: From 26957ac68376c7ca1bca0c9f7699df112f517a05 Mon Sep 17 00:00:00 2001 From: Claude Date: Fri, 11 Sep 2026 12:36:59 +0000 Subject: [PATCH 2/3] Drop the stale cffi pin when installing aws-encryption-sdk-python's test requirements Ubuntu 26.04 ships GCC 15, which rejects the implicit function declaration in cffi 1.15.1's _cffi_backend.c that GCC 13 only warned about, so the source build for Python 3.14 fails. The pin is replaced by cryptography's own cffi requirement as soon as cryptography is installed, so skipping it changes nothing about what the tests run against. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01EkX3LD8jYgtCyGDVRUq6cr --- .github/downstream.d/aws-encryption-sdk-python.sh | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/downstream.d/aws-encryption-sdk-python.sh b/.github/downstream.d/aws-encryption-sdk-python.sh index c4faaf6ef4e4..75432732cb0a 100755 --- a/.github/downstream.d/aws-encryption-sdk-python.sh +++ b/.github/downstream.d/aws-encryption-sdk-python.sh @@ -4,7 +4,9 @@ case "${1}" in install) cd aws-encryption-sdk-python uv pip install -e . - uv pip install -r test/upstream-requirements-py311.txt + # cffi 1.15.1 cannot be built for Python 3.14 with GCC 14+, and + # installing cryptography below replaces it with a current cffi anyway. + uv pip install -r <(grep -v '^cffi==' test/upstream-requirements-py311.txt) ;; run) cd aws-encryption-sdk-python From 29c4cf560ee4b0c522bc7540e13a80f914edf8d1 Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 17 Sep 2026 21:07:01 +0000 Subject: [PATCH 3/3] Bump aws-encryption-sdk-python in CI and drop the cffi workaround aws-encryption-sdk-python's test requirements now pin a cffi that builds on Python 3.14 with GCC 15, so the downstream script can install the requirements file unmodified again. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01EkX3LD8jYgtCyGDVRUq6cr --- .github/downstream.d/aws-encryption-sdk-python.sh | 4 +--- .github/workflows/ci.yml | 4 ++-- 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/.github/downstream.d/aws-encryption-sdk-python.sh b/.github/downstream.d/aws-encryption-sdk-python.sh index 75432732cb0a..c4faaf6ef4e4 100755 --- a/.github/downstream.d/aws-encryption-sdk-python.sh +++ b/.github/downstream.d/aws-encryption-sdk-python.sh @@ -4,9 +4,7 @@ case "${1}" in install) cd aws-encryption-sdk-python uv pip install -e . - # cffi 1.15.1 cannot be built for Python 3.14 with GCC 14+, and - # installing cryptography below replaces it with a current cffi anyway. - uv pip install -r <(grep -v '^cffi==' test/upstream-requirements-py311.txt) + uv pip install -r test/upstream-requirements-py311.txt ;; run) cd aws-encryption-sdk-python diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 6d87408ac453..ed38e12585ff 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -395,8 +395,8 @@ jobs: PATH: twisted - DOWNSTREAM: aws-encryption-sdk-python REPO: awslabs/aws-encryption-sdk-python - # Latest commit on the aws-encryption-sdk-python master branch, as of Sep 05, 2026. - REF: 401c9bb215b45f344f6769534f2e7fac261edd36 + # Latest commit on the aws-encryption-sdk-python master branch, as of Sep 17, 2026. + REF: a6c0413bb0ddc9bccdefad9f1d2c031e0bc4db29 PATH: aws-encryption-sdk-python - DOWNSTREAM: certbot REPO: certbot/certbot