docs(mcp-server): correct stale libstdc++ guidance, add distroless gotchas - #12
Merged
Merged
Conversation
…tchas The profile claimed the Hummingbird Python runtime does not include libstdc++.so.6. That is no longer true — verified 2026-08-30 in both :latest and :latest-fips (6.0.36). Containerfiles still carrying the copy-forward workaround can drop it. libgomp remains absent from both runtime and builder; PyTorch bundles its own, so torch-based servers are unaffected, but packages expecting the system copy still fail. Adds a symptom-to-fix table for distroless failures. The build-time ones are loud and self-explaining; the dangerous class is third-party native libraries that shell out at import time without checking the result, which fail as a bare SIGSEGV with no traceback and no stderr. Documents that /etc/machine-id must be POPULATED, not empty. The empty "first boot" state does not short-circuit the fallback probe. Measured against onnxruntime 1.29.0 on quay.io/hummingbird/python:latest with telemetry enabled: absent -> SIGSEGV (139) empty -> SIGSEGV (139) populated -> imports cleanly Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013t1uJRVqhkikr52jXxxvck
…coverage The two registry paths differ. registry.access.redhat.com/hi/python:3.12 ships both libstdc++ and libgomp; quay.io/hummingbird/python:latest ships libstdc++ only. A Containerfile on the hi/ path that still dnf-installs both and copies them forward is doing redundant work. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013t1uJRVqhkikr52jXxxvck
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Corrects guidance that no longer matches the base images, and documents the distroless failure modes hit while fixing HUM-6564 in
crunchtools/memory.libstdc++.so.6. It does now. Containerfiles still carrying the copy-forward workaround can drop it.registry.access.redhat.com/hi/python:3.12ships bothlibstdc++andlibgomp;quay.io/hummingbird/python:latestshipslibstdc++only./etc/machine-idmust be populated, not empty. The systemd "first boot" empty-file state does not short-circuit the fallback probe.Test plan
Measured against onnxruntime 1.29.0 with telemetry enabled:
/etc/machine-idNative library presence verified 2026-09-01 by inspecting
/usr/lib64in each runtime image directly.Applied in practice: crunchtools/memory#4, deployed to lotor and running onnxruntime 1.29.0 unpinned.
🤖 Generated with Claude Code
https://claude.ai/code/session_013t1uJRVqhkikr52jXxxvck