From 001b59cde5eb008e9bc43248ff918a5aefdee9d0 Mon Sep 17 00:00:00 2001 From: Thomas Waldmann Date: Sun, 27 Sep 2026 15:53:44 +0200 Subject: [PATCH] CI: force-reinstall cryptography from source for the linux binaries The moto S3 test server install already pulls in the cryptography manylinux wheel, so a plain "pip install --no-binary cryptography" kept that wheel (statically linked OpenSSL) and the dynamic libcrypto check failed. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/ci.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a59e3f6ef5..a8e6cf8942 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -323,7 +323,9 @@ jobs: run: | set -euxo pipefail rustc --version - pip install --no-binary cryptography cryptography + # --force-reinstall: the moto S3 test server install above already pulled in the + # cryptography wheel, without it pip would just keep that one. + pip install --force-reinstall --no-binary cryptography cryptography # check that the extension links the system OpenSSL dynamically and # loads the same version as the system's openssl program rust_ext=$(python -c 'import cryptography.hazmat.bindings._rust as m; print(m.__file__)')