Skip to content

Add ARM64 Linux Snap builds with selectable core22/core24 bases - #338607

Open
Dr Bill Mcilhargey (billmcilhargey) wants to merge 4 commits into
microsoft:mainfrom
billmcilhargey:feat-snapd-arm64-support
Open

Dr Bill Mcilhargey (billmcilhargey) wants to merge 4 commits into
microsoft:mainfrom
billmcilhargey:feat-snapd-arm64-support

Conversation

@billmcilhargey

@billmcilhargey Dr Bill Mcilhargey (billmcilhargey) commented Sep 29, 2026 •

Copy link
Copy Markdown

Build ARM64 Linux Snap artifacts from native-architecture staged libraries, keeping core24 as the default and offering core22 for unpublished validation builds.

Changes

  • Use pinned amd64/arm64 Snapcraft 8 builders with matching Ubuntu package mirrors; reject mislabeled executable architectures before packing.
  • Render base-specific Snapcraft architecture syntax, desktop libraries, and RPATH. The launcher reads the installed snap's base rather than hard-coding core20/core24.
  • Wire the ARM64 product artifact and sanity target, add focused packaging tests, and document native install and release gates. Core26 can be packed locally on native Ubuntu 26.04 with Snapcraft 9+, but is not enabled in product CI without a verified multiarch builder.

Related

Refs #125120 and #269552. Related to base/runtime report #241636. This is a follow-up/alternative to #298237 and #271464; please coordinate overlapping changes rather than merging both independently. It does not claim to fix their separate alternatives-registration or terminal-environment work. Do not close the ARM64 issues until snaps are available in the Store.

Validation and remaining work

  • Merged upstream Engineering - decompose Linux stage #338552 in signed commit 31aa255; the Snap package step now runs in the split Linux Sign job, and the x64/ARM64 stages receive the Snap base and build flags. GitHub reports the PR as mergeable.
  • node --test build/lib/test/buildSnap.test.ts: 35 passing after resolving the Linux-stage split conflicts.
  • Shell syntax, patch whitespace, changed Azure YAML files, and six rendered base/architecture manifests validated; TypeScript editor diagnostics clear. The five initial hygiene errors and two Copilot review findings were addressed in ae3f271, and the follow-up ESLint warning was fixed in f398591. Compile & Hygiene now passes on the current head; other CI jobs may still be running.
  • Not yet verified: an Azure product Snap build, native Ubuntu ARM64 install/desktop test, or Snap Store promotion. Before merge, run an unpublished product build (VSCODE_PUBLISH=false, VSCODE_RUN_ARTIFACT_SANITY_TESTS=true) and complete native ARM64 validation. The ARM64 artifact sanity job currently downloads the snap but cannot launch it on the x64 runner.

Policy / maintainer coordination

The VS Code PR Check currently fails because a community-classified PR may not modify protected engineering files under build/ or build/azure-pipelines/. The check requires a team-member-authored PR, a head commit signed by a trusted team-member key, or authorized automation; simply making this commit GitHub Verified would not satisfy it. Please have a VS Code build maintainer review and adopt/cherry-pick the relevant changes rather than bypassing the policy. This PR is for review and coordination, not an assertion that the release gate has passed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Core22 publishing remains insufficiently gated, and privileged QEMU setup uses a mutable image tag.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds ARM64 Snap packaging, updates the default base to core24, and supports unpublished core22 validation builds.

Changes:

  • Adds architecture-aware Snapcraft manifests, builders, libraries, and launcher paths.
  • Produces and sanity-checks ARM64 Snap artifacts.
  • Adds focused packaging tests and release-validation documentation.
File Description
test/​sanity/​src/​desktop.test.ts Adds ARM64 Snap sanity coverage.
test/​sanity/​src/​context.ts Registers and verifies Snap artifacts.
resources/​linux/​snap/​snapcraft.yaml Templates base, architecture, libraries, and RPATH.
resources/​linux/​snap/​README.md Documents build and release validation.
resources/​linux/​snap/​electron-launch Resolves runtime paths from Snap metadata.
build/​linux/​snapcraftConfig.ts Defines base- and architecture-specific configuration.
build/​lib/​test/​buildSnap.test.ts Tests manifests, builders, and launch behavior.
build/​gulpfile.vscode.linux.ts Renders the Snapcraft template.
build/​azure-pipelines/​product-build.yml Wires build parameters and artifact sanity jobs.
build/​azure-pipelines/​product-build-template.yml Mirrors Snap build configuration.
build/​azure-pipelines/​product-build-ado-ci.yml Updates the Snap parameter label.
build/​azure-pipelines/​linux/​steps/​product-build-linux-compile.yml Builds x64 and ARM64 Snaps.
build/​azure-pipelines/​linux/​snapcraft-ubuntu-24-arm64.sources Adds Noble ARM64 mirrors.
build/​azure-pipelines/​linux/​snapcraft-ubuntu-24-amd64.sources Adds Noble amd64 mirrors.
build/​azure-pipelines/​linux/​snapcraft-ubuntu-22-arm64.list Adds Jammy ARM64 mirrors.
build/​azure-pipelines/​linux/​snapcraft-ubuntu-22-amd64.list Adds Jammy amd64 mirrors.
build/​azure-pipelines/​linux/​snapcraft-apt-retries.conf Configures Apt retries.
build/​azure-pipelines/​linux/​product-build-linux.yml Propagates the selected Snap base.
build/​azure-pipelines/​linux/​build-snap.sh Validates and packages architecture-matched Snaps.
.github/​skills/​azure-pipelines/​SKILL.md Documents new pipeline options.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread build/azure-pipelines/linux/steps/product-build-linux-compile.yml Outdated
Comment thread build/azure-pipelines/product-build.yml
@billmcilhargey
Dr Bill Mcilhargey (billmcilhargey) marked this pull request as ready for review September 29, 2026 04:31
@billmcilhargey

Copy link
Copy Markdown
Author

Native ARM64 validation proposal (not yet implemented): GitHub offers a VM runner labeled ubuntu-24.04-arm (and ubuntu-22.04-arm / ubuntu-26.04-arm for the corresponding bases): https://docs.github.com/en/actions/reference/runners/github-hosted-runners. Use it for an install-and-launch smoke check of the exact ARM64 snap produced by an unpublished Azure Product build, not as a substitute for that product build. The 24.04 ARM64 runner image configures snapd, but the job should verify dpkg --print-architecture is arm64 and snapd.socket is ready.

Artifact handoff must be trusted: forked PR Actions jobs cannot access Azure/organization secrets (https://docs.github.com/en/code-security/reference/secret-security/secret-types). Prefer a maintainer-owned manual workflow_dispatch on trusted code with a scoped, read-only artifact source (or a provisioned native Ubuntu ARM64 Azure pool so DownloadPipelineArtifact@2 stays within the product pipeline). Do not run fork-controlled code under pull_request_target with release credentials.

Repro gate: download and hash-check vscode_client_linux_arm64_snap from the same product build, sudo snap install --dangerous --classic it on the native VM, check meta/snap.yaml and the executable's ELF architecture, then launch the actual /snap/bin/code-insiders GUI path under Xvfb/DBus and exercise Open Folder, integrated/external terminals, and extension installation. Remove the snap afterward. This must be tested before claiming ARM64 Store readiness.

Current limitations: ArtifactSanityTestsLinux uses --no-detection on the x64 runner for the ARM64 target, so it only downloads it. In test/sanity/src/context.ts, installSnap() returns the raw /snap/<name>/current/usr/share/<name>/<name> binary for Playwright, and verifySnapLauncher() checks /snap/bin/<name> --version only. The UI test therefore does not yet prove that the GUI works when launched through snapd and electron-launch. Keep this PR draft until a real wrapper-launched native ARM64 run succeeds and the protected build changes are adopted by a trusted maintainer.

@vs-code-engineering

vs-code-engineering Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

📬 CODENOTIFY

The following users are being notified based on files changed in this PR:

Ladislau Szomoru (@lszomoru)

Matched files:

  • build/azure-pipelines/linux/build-snap.sh
  • build/azure-pipelines/linux/product-build-linux-jobs.yml
  • build/azure-pipelines/linux/product-build-linux.yml
  • build/azure-pipelines/linux/snapcraft-apt-retries.conf
  • build/azure-pipelines/linux/snapcraft-ubuntu-22-amd64.list
  • build/azure-pipelines/linux/snapcraft-ubuntu-22-arm64.list
  • build/azure-pipelines/linux/snapcraft-ubuntu-24-amd64.sources
  • build/azure-pipelines/linux/snapcraft-ubuntu-24-arm64.sources
  • build/azure-pipelines/linux/steps/product-build-linux-compile.yml
  • build/azure-pipelines/linux/steps/product-build-linux-package.yml
  • build/azure-pipelines/linux/steps/product-build-linux-setup.yml
  • build/azure-pipelines/product-build-ado-ci.yml
  • build/azure-pipelines/product-build-template.yml
  • build/azure-pipelines/product-build-variables.yml
  • build/azure-pipelines/product-build.yml

Dmitriy Vasyura (@dmitrivMS)

Matched files:

  • test/sanity/src/context.ts
  • test/sanity/src/desktop.test.ts

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@billmcilhargey

Copy link
Copy Markdown
Author

Reviewer guide — implementation and remaining gates

Why: The ARM64 request (#125120; duplicate #269552) cannot be satisfied by labeling an amd64 snap as arm64: the Electron binary and staged Ubuntu libraries must match the target architecture. This PR builds both architecture-specific snaps; it does not publish them to the Snap Store.

What to review, in build order:

  1. build/azure-pipelines/product-build.yml, product-build-template.yml, and product-build-variables.yml enable x64 and ARM64 stages for Snap-only builds and pass the selected base through the split Linux job graph. linux/product-build-linux-jobs.yml passes it to the Sign job; linux/steps/product-build-linux-package.yml prepares and packs the snap after the compiled client and CLI are combined. Signed merge commit 31aa2557dc9 adapts this flow to upstream's Compile/Test/Sign split (Engineering - decompose Linux stage #338552); GitHub now reports the branch mergeable.
  2. build/linux/snapcraftConfig.ts, build/gulpfile.vscode.linux.ts, resources/linux/snap/snapcraft.yaml, and electron-launch select the base-specific architecture syntax, staged libraries, crash-handler RPATH, and runtime paths. core24 is the product default; core22 is an opt-in validation build with publish/release explicitly blocked; core26 is only a guarded local build on native Ubuntu 26.04 with Snapcraft 9 (no verified CI image).
  3. build/azure-pipelines/linux/build-snap.sh checks the client ELF architecture and uses pinned multiarch Snapcraft containers plus the correct Jammy/Noble Apt sources. The privileged ARM64 QEMU image is also pinned by digest. test/sanity gains ARM64 artifact lookup and a launcher --version check; build/lib/test/buildSnap.test.ts covers packaging paths and base/architecture combinations.

Evidence: 35 focused Snap tests pass; ten Azure pipeline YAML files and six rendered Snap manifests parsed after the Linux-stage merge; the current Compile & Hygiene check passes. The earlier Copilot review comments (core22 publication guard and privileged QEMU pin) are resolved.

Not yet evidence of a working Store release: No Azure product Snap build or native Ubuntu ARM64 GUI installation has been run. The ARM64 artifact sanity job only downloads the artifact on an x64 runner, and the Playwright UI test currently launches the raw Electron binary rather than the snap's /snap/bin GUI wrapper. A maintainer should test the exact unpublished product snap on native ARM64 (ideally an approved ubuntu-24.04-arm VM or native Azure pool), including startup, Open Folder, terminals, and extension installation; see the earlier runner proposal. Store promotion is a separate authorized release step. VS Code PR Check remains a protected-engineering-files policy failure requiring trusted maintainer adoption, not another conflict resolution.

This overlaps #298237 and #271464; coordinate or cherry-pick the packaging work rather than merging overlapping alternatives independently. It does not include the separate alternatives-registration or terminal-environment changes proposed there.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Sponsor
SponsoredKunjungi sekarang
Promo