Skip to content

docs(mcp-server): correct stale libstdc++ guidance, add distroless gotchas - #12

Merged
fatherlinux merged 2 commits into
mainfrom
docs/distroless-gotchas
Sep 1, 2026
Merged

fatherlinux merged 2 commits into
mainfrom
docs/distroless-gotchas

Conversation

@fatherlinux

Copy link
Copy Markdown
Member

Summary

Corrects guidance that no longer matches the base images, and documents the distroless failure modes hit while fixing HUM-6564 in crunchtools/memory.

  • Stale claim removed. The profile said the Hummingbird Python runtime has no libstdc++.so.6. It does now. Containerfiles still carrying the copy-forward workaround can drop it.
  • The two registry paths differ. registry.access.redhat.com/hi/python:3.12 ships both libstdc++ and libgomp; quay.io/hummingbird/python:latest ships libstdc++ only.
  • Gotchas table. Symptom → cause → fix. Build-time failures are loud; the dangerous class is third-party native libraries that shell out at import time without checking the result and die as a bare SIGSEGV with no traceback.
  • /etc/machine-id must be populated, not empty. The systemd "first boot" empty-file state does not short-circuit the fallback probe.

Test plan

Measured against onnxruntime 1.29.0 with telemetry enabled:

/etc/machine-id result
absent SIGSEGV (139)
present, empty SIGSEGV (139)
present, populated imports cleanly

Native library presence verified 2026-09-01 by inspecting /usr/lib64 in each runtime image directly.

Applied in practice: crunchtools/memory#4, deployed to lotor and running onnxruntime 1.29.0 unpinned.

🤖 Generated with Claude Code

https://claude.ai/code/session_013t1uJRVqhkikr52jXxxvck

fatherlinux and others added 2 commits August 30, 2026 17:37
…tchas

The profile claimed the Hummingbird Python runtime does not include
libstdc++.so.6. That is no longer true — verified 2026-08-30 in both
:latest and :latest-fips (6.0.36). Containerfiles still carrying the
copy-forward workaround can drop it. libgomp remains absent from both
runtime and builder; PyTorch bundles its own, so torch-based servers are
unaffected, but packages expecting the system copy still fail.

Adds a symptom-to-fix table for distroless failures. The build-time ones
are loud and self-explaining; the dangerous class is third-party native
libraries that shell out at import time without checking the result, which
fail as a bare SIGSEGV with no traceback and no stderr.

Documents that /etc/machine-id must be POPULATED, not empty. The empty
"first boot" state does not short-circuit the fallback probe. Measured
against onnxruntime 1.29.0 on quay.io/hummingbird/python:latest with
telemetry enabled:

  absent    -> SIGSEGV (139)
  empty     -> SIGSEGV (139)
  populated -> imports cleanly

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013t1uJRVqhkikr52jXxxvck
…coverage

The two registry paths differ. registry.access.redhat.com/hi/python:3.12
ships both libstdc++ and libgomp; quay.io/hummingbird/python:latest ships
libstdc++ only. A Containerfile on the hi/ path that still dnf-installs
both and copies them forward is doing redundant work.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013t1uJRVqhkikr52jXxxvck
@fatherlinux
fatherlinux merged commit e1e29fc into main Sep 1, 2026
2 checks passed
@fatherlinux
fatherlinux deleted the docs/distroless-gotchas branch September 1, 2026 17:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant