Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

use glibc buildimage for custom clang #35617

Merged
merged 2 commits into from
Mar 28, 2025
Merged

Conversation

brycekahle
Copy link
Member

What does this PR do?

Uses the glibc buildimages to build the custom version of clang we use for ebpf compilation

Motivation

Standardizing on a buildimage

Describe how you validated your changes

Ran pipelines of full KMT suite using this new built version of clang.

Possible Drawbacks / Trade-offs

Additional Notes

Added versioning to the built clang, so we don't accidentally clobber anything. Currently doesn't force a . separator, so that it is backwards compatible with the current filenames. A future PR will update to using only the versioned files.

@brycekahle brycekahle added changelog/no-changelog team/ebpf-platform qa/done QA done before merge and regressions are covered by tests labels Mar 28, 2025
@brycekahle brycekahle requested review from a team as code owners March 28, 2025 17:48
@brycekahle brycekahle added the ask-review Ask required teams to review this PR label Mar 28, 2025
@github-actions github-actions bot added component/system-probe medium review PR review might take time labels Mar 28, 2025
Copy link
Contributor

@gjulianm gjulianm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, but I'd rebase on main before merging to ensure that #35549 doesn't break this PR

@brycekahle
Copy link
Member Author

to ensure that #35549 doesn't break this PR

This PR doesn't use the new built clang yet. I'll do that in a future PR, so I'll make sure it has that change and doesn't break.

Copy link
Contributor

@ofek ofek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for updating the other tags as well, looks great to me!

@agent-platform-auto-pr
Copy link
Contributor

Gitlab CI Configuration Changes

Modified Jobs

variables (configuration)
  variables:
    AGENT_API_KEY_ORG2: agent-api-key-org-2
    AGENT_APP_KEY_ORG2: agent-ci-app-key-org-2
    AGENT_BINARIES_DIR: bin/agent
    AGENT_GITHUB_APP: agent-github-app
    AGENT_QA_E2E: agent-qa-e2e
    API_KEY_ORG2: ci.datadog-agent.datadog_api_key_org2
    ARTIFACT_DOWNLOAD_ATTEMPTS: 2
    ATLASSIAN_WRITE: atlassian-write
    BTFHUB_ARCHIVE_BRANCH: main
    BUCKET_BRANCH: dev
    CHANGELOG_COMMIT_SHA: ci.datadog-agent.gitlab_changelog_commit_sha
    CHOCOLATEY_API_KEY: ci.datadog-agent.chocolatey_api_key
    CI_IMAGE_BTF_GEN: v59857552-25d5753f
    CI_IMAGE_BTF_GEN_SUFFIX: ''
    CI_IMAGE_DD_AGENT_TESTING: v59857552-25d5753f
    CI_IMAGE_DD_AGENT_TESTING_SUFFIX: ''
    CI_IMAGE_DEB_ARM64: v59857552-25d5753f
    CI_IMAGE_DEB_ARM64_SUFFIX: ''
    CI_IMAGE_DEB_ARMHF: v59857552-25d5753f
    CI_IMAGE_DEB_ARMHF_SUFFIX: ''
    CI_IMAGE_DEB_X64: v59857552-25d5753f
    CI_IMAGE_DEB_X64_SUFFIX: ''
    CI_IMAGE_DOCKER_ARM64: v59857552-25d5753f
    CI_IMAGE_DOCKER_ARM64_SUFFIX: ''
    CI_IMAGE_DOCKER_X64: v59857552-25d5753f
    CI_IMAGE_DOCKER_X64_SUFFIX: ''
    CI_IMAGE_GITLAB_AGENT_DEPLOY: v59857552-25d5753f
    CI_IMAGE_GITLAB_AGENT_DEPLOY_SUFFIX: ''
    CI_IMAGE_LINUX_GLIBC_2_17_X64: v59857552-25d5753f
    CI_IMAGE_LINUX_GLIBC_2_17_X64_SUFFIX: ''
    CI_IMAGE_LINUX_GLIBC_2_23_ARM64: v59857552-25d5753f
    CI_IMAGE_LINUX_GLIBC_2_23_ARM64_SUFFIX: ''
    CI_IMAGE_RPM_ARM64: v59857552-25d5753f
    CI_IMAGE_RPM_ARM64_SUFFIX: ''
    CI_IMAGE_RPM_ARMHF: v59857552-25d5753f
    CI_IMAGE_RPM_ARMHF_SUFFIX: ''
    CI_IMAGE_RPM_X64: v59857552-25d5753f
    CI_IMAGE_RPM_X64_SUFFIX: ''
    CI_IMAGE_SYSTEM_PROBE_ARM64: v59857552-25d5753f
    CI_IMAGE_SYSTEM_PROBE_ARM64_SUFFIX: ''
    CI_IMAGE_SYSTEM_PROBE_X64: v59857552-25d5753f
    CI_IMAGE_SYSTEM_PROBE_X64_SUFFIX: ''
    CI_IMAGE_WIN_LTSC2022_X64: v59857552-25d5753f
    CI_IMAGE_WIN_LTSC2022_X64_SUFFIX: ''
+   CLANG_BUILD_VERSION: ''
    CLANG_LLVM_VER: 12.0.1
    CLUSTER_AGENT_BINARIES_DIR: bin/datadog-cluster-agent
    CLUSTER_AGENT_CLOUDFOUNDRY_BINARIES_DIR: bin/datadog-cluster-agent-cloudfoundry
    CODECOV: codecov
    CODECOV_TOKEN: ci.datadog-agent.codecov_token
    CWS_INSTRUMENTATION_BINARIES_DIR: bin/cws-instrumentation
-   DATADOG_AGENT_ARMBUILDIMAGES: v59857552-25d5753f
+   DATADOG_AGENT_ARMBUILDIMAGES: v60221061-324ab098
    DATADOG_AGENT_ARMBUILDIMAGES_SUFFIX: ''
-   DATADOG_AGENT_BTF_GEN_BUILDIMAGES: v59857552-25d5753f
+   DATADOG_AGENT_BTF_GEN_BUILDIMAGES: v60221061-324ab098
    DATADOG_AGENT_BTF_GEN_BUILDIMAGES_SUFFIX: ''
-   DATADOG_AGENT_BUILDIMAGES: v59857552-25d5753f
+   DATADOG_AGENT_BUILDIMAGES: v60221061-324ab098
    DATADOG_AGENT_BUILDIMAGES_SUFFIX: ''
    DATADOG_AGENT_EMBEDDED_PATH: /opt/datadog-agent/embedded
-   DATADOG_AGENT_SYSPROBE_BUILDIMAGES: v59857552-25d5753f
+   DATADOG_AGENT_SYSPROBE_BUILDIMAGES: v60221061-324ab098
    DATADOG_AGENT_SYSPROBE_BUILDIMAGES_SUFFIX: ''
-   DATADOG_AGENT_WINBUILDIMAGES: v59857552-25d5753f
+   DATADOG_AGENT_WINBUILDIMAGES: v60221061-324ab098
    DATADOG_AGENT_WINBUILDIMAGES_SUFFIX: ''
    DD_AGENT_TESTING_DIR: $CI_PROJECT_DIR/test/new-e2e/tests
    DD_PKG_VERSION: latest
    DEB_GPG_KEY: ci.datadog-agent.deb_signing_private_key_${DEB_GPG_KEY_ID}
    DEB_GPG_KEY_ID: c0962c7d
    DEB_GPG_KEY_NAME: Datadog, Inc. APT key
    DEB_RPM_TESTING_BUCKET_BRANCH: testing
    DEB_S3_BUCKET: apt.datad0g.com
    DEB_SIGNING_PASSPHRASE: ci.datadog-agent.deb_signing_key_passphrase_${DEB_GPG_KEY_ID}
    DEB_TESTING_S3_BUCKET: apttesting.datad0g.com
    DOCKER_REGISTRY_LOGIN: ci.datadog-agent.docker_hub_login
    DOCKER_REGISTRY_PWD: ci.datadog-agent.docker_hub_pwd
    DOCKER_REGISTRY_RO: dockerhub-readonly
    DOCKER_REGISTRY_URL: docker.io
    DOGSTATSD_BINARIES_DIR: bin/dogstatsd
    E2E_AZURE: e2e-azure
    E2E_GCP: e2e-gcp
    EXECUTOR_JOB_SECTION_ATTEMPTS: 2
    FF_KUBERNETES_HONOR_ENTRYPOINT: true
    FF_SCRIPT_SECTIONS: 1
    FF_TIMESTAMPS: true
    GENERAL_ARTIFACTS_CACHE_BUCKET_URL: https://dd-agent-omnibus.s3.amazonaws.com
    GET_SOURCES_ATTEMPTS: 2
    GITLAB_TOKEN: gitlab-token
    GO_TEST_SKIP_FLAKE: 'true'
    INSTALLER_TESTING_S3_BUCKET: installtesting.datad0g.com
    INSTALL_SCRIPT_API_KEY_ORG2: install-script-api-key-org-2
    INTEGRATION_WHEELS_CACHE_BUCKET: dd-agent-omnibus
    KERNEL_MATRIX_TESTING_ARM_AMI_ID: ami-0b5f838a19d37fc61
    KERNEL_MATRIX_TESTING_X86_AMI_ID: ami-05b3973acf5422348
    KITCHEN_INFRASTRUCTURE_FLAKES_RETRY: 2
    MACOS_GITHUB_APP_1: macos-github-app-one
    MACOS_GITHUB_APP_2: macos-github-app-two
    MACOS_S3_BUCKET: dd-agent-macostesting
    OMNIBUS_BASE_DIR: /omnibus
    OMNIBUS_GIT_CACHE_DIR: /tmp/omnibus-git-cache
    OMNIBUS_PACKAGE_DIR: $CI_PROJECT_DIR/omnibus/pkg/
    OMNIBUS_PACKAGE_DIR_SUSE: $CI_PROJECT_DIR/omnibus/suse/pkg
    PIPELINE_KEY_ALIAS: alias/ci_datadog-agent_pipeline-key
    PROCESS_S3_BUCKET: datad0g-process-agent
    RELEASE_VERSION: nightly
    RESTORE_CACHE_ATTEMPTS: 2
    RPM_GPG_KEY: ci.datadog-agent.rpm_signing_private_key_${RPM_GPG_KEY_ID}
    RPM_GPG_KEY_ID: b01082d3
    RPM_GPG_KEY_NAME: Datadog, Inc. RPM key
    RPM_S3_BUCKET: yum.datad0g.com
    RPM_SIGNING_PASSPHRASE: ci.datadog-agent.rpm_signing_key_passphrase_${RPM_GPG_KEY_ID}
    RPM_TESTING_S3_BUCKET: yumtesting.datad0g.com
    RUN_E2E_TESTS: auto
    RUN_KMT_TESTS: auto
    RUN_UNIT_TESTS: auto
    S3_ARTIFACTS_URI: s3://dd-ci-artefacts-build-stable/$CI_PROJECT_NAME/$CI_PIPELINE_ID
    S3_CP_CMD: aws s3 cp $S3_CP_OPTIONS
    S3_CP_OPTIONS: --no-progress --region us-east-1 --sse AES256
    S3_DD_AGENT_OMNIBUS_BTFS_URI: s3://dd-agent-omnibus/btfs
    S3_DD_AGENT_OMNIBUS_JAVA_URI: s3://dd-agent-omnibus/openjdk
    S3_DD_AGENT_OMNIBUS_LLVM_URI: s3://dd-agent-omnibus/llvm
    S3_DSD6_URI: s3://dsd6-staging
    S3_OMNIBUS_CACHE_BUCKET: dd-ci-datadog-agent-omnibus-cache-build-stable
    S3_OMNIBUS_GIT_CACHE_BUCKET: dd-ci-datadog-agent-omnibus-git-cache-build-stable
    S3_PERMANENT_ARTIFACTS_URI: s3://dd-ci-persistent-artefacts-build-stable/$CI_PROJECT_NAME
    S3_PROJECT_ARTIFACTS_URI: s3://dd-ci-artefacts-build-stable/$CI_PROJECT_NAME
    S3_RELEASE_ARTIFACTS_URI: s3://dd-release-artifacts/$CI_PROJECT_NAME/$CI_PIPELINE_ID
    S3_RELEASE_INSTALLER_ARTIFACTS_URI: s3://dd-release-artifacts/datadog-installer/$CI_PIPELINE_ID
    S3_SBOM_STORAGE_URI: s3://sbom-root-us1-ddbuild-io/$CI_PROJECT_NAME/$CI_PIPELINE_ID
    SLACK_AGENT: slack-agent-ci
    SMP_ACCOUNT: smp
    STATIC_BINARIES_DIR: bin/static
    SYSTEM_PROBE_BINARIES_DIR: bin/system-probe
    VCPKG_BLOB_SAS_URL: ci.datadog-agent-buildimages.vcpkg_blob_sas_url
    WINDOWS_BUILDS_S3_BUCKET: $WIN_S3_BUCKET/builds
    WINDOWS_POWERSHELL_DIR: $CI_PROJECT_DIR/signed_scripts
    WINDOWS_TESTING_S3_BUCKET: pipelines/A7/$CI_PIPELINE_ID
    WINGET_PAT: ci.datadog-agent.winget_pat
    WIN_S3_BUCKET: dd-agent-mstesting
.agent_build_common
  .agent_build_common:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - echo "About to build for $RELEASE_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --flavor "$FLAVOR" --config-directory "$CONFIG_DIR" --install-directory "$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    variables:
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
.agent_build_script
  .agent_build_script:
  - echo "About to build for $RELEASE_VERSION"
  - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
    || exit 101
  - rm -f modcache.tar.xz
  - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
  - rm -rf $OMNIBUS_PACKAGE_DIR/*
  - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
  - mkdir -p /tmp/system-probe
- - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
- - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+ - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+   /tmp/system-probe/clang-bpf
+ - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+   /tmp/system-probe/llc-bpf
  - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
  - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
  - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
    --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
    --flavor "$FLAVOR" --config-directory "$CONFIG_DIR" --install-directory "$INSTALL_DIR"
  - ls -la $OMNIBUS_PACKAGE_DIR
  - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
.build_clang_common
  .build_clang_common:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $CI_PROJECT_DIR/.tmp/clang
      - $CI_PROJECT_DIR/.tmp/llc
+     - $CI_PROJECT_DIR/.tmp/llvm-strip
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - allow_failure: true
      when: manual
    script:
    - mkdir /tmp/clangbuild && cd /tmp/clangbuild
    - CLANG_MAJOR_VER=$(echo "${CLANG_LLVM_VER}" | cut -d '.' -f 1)
    - CLANG_SHA256SUM=6e912133bcf56e9cfe6a346fa7e5c52c2cde3e4e48b7a6cc6fcc7c75047da45f
    - LLVM_SHA256SUM=7d9a8405f557cefc5a21bf5672af73903b64749d9bc3a50322239f56f34ffddf
    - wget ${GENERAL_ARTIFACTS_CACHE_BUCKET_URL}/llvm/clang-${CLANG_LLVM_VER}.src.tar.xz
      -O clang.src.tar.xz
    - wget ${GENERAL_ARTIFACTS_CACHE_BUCKET_URL}/llvm/llvm-${CLANG_LLVM_VER}.src.tar.xz
      -O llvm.src.tar.xz
    - echo -e "${LLVM_SHA256SUM} llvm.src.tar.xz\n${CLANG_SHA256SUM} clang.src.tar.xz"
      | sha256sum --check -
    - mkdir clang && tar xf clang.src.tar.xz --strip-components=1 --no-same-owner -C
      clang
    - mkdir llvm && tar xf llvm.src.tar.xz --strip-components=1 --no-same-owner -C llvm
    - mkdir build && cd build
    - cp ../llvm/Modules/* ../llvm/cmake/modules || echo "LLVM common cmake utils not
      found in directory 'Modules'"
    - patch -ruN ../llvm/CMakeLists.txt < $CI_PROJECT_DIR/pkg/ebpf/c/cmakelists.patch
    - patch -ruN ../llvm/lib/Analysis/ConstantFolding.cpp < $CI_PROJECT_DIR/pkg/ebpf/c/constant_folding.patch
+   - 'cmake \
+ 
-   - 'cmake -DLLVM_ENABLE_PROJECTS=clang \
?   - ------
+     -DLLVM_ENABLE_PROJECTS=clang \
  
      -DLLVM_TARGETS_TO_BUILD="BPF" \
  
      -DCMAKE_INSTALL_PREFIX=$DATADOG_AGENT_EMBEDDED_PATH \
  
      -G "Ninja" \
  
      -DCMAKE_BUILD_TYPE=MinSizeRel \
+ 
+     -DCMAKE_SYSTEM_PROCESSOR=$CMAKE_SYSTEM_PROCESSOR \
+ 
+     -DCMAKE_SYSTEM_NAME=$CMAKE_SYSTEM_NAME \
+ 
+     -DCMAKE_RANLIB=$CMAKE_RANLIB \
+ 
+     -DCMAKE_AR=$CMAKE_AR \
+ 
+     -DCMAKE_C_COMPILER=$CMAKE_C_COMPILER \
+ 
+     -DCMAKE_CXX_COMPILER=$CMAKE_CXX_COMPILER \
+ 
+     -DCMAKE_FIND_ROOT_PATH=$CMAKE_FIND_ROOT_PATH \
+ 
+     -DCMAKE_FIND_ROOT_PATH_MODE_PACKAGE=$CMAKE_FIND_ROOT_PATH_MODE_PACKAGE \
  
      -DLLVM_BUILD_TOOLS=ON \
  
      -DLLVM_ENABLE_TERMINFO=OFF \
  
      -DLLVM_INCLUDE_EXAMPLES=OFF \
  
      -DLLVM_INCLUDE_TESTS=OFF \
  
      -DLLVM_INCLUDE_BENCHMARKS=OFF \
  
      -DLLVM_STATIC_LINK_CXX_STDLIB=ON \
  
      -DLLVM_ENABLE_BINDINGS=OFF \
  
      -DLLVM_PARALLEL_COMPILE_JOBS=4 \
  
      -DLLVM_PARALLEL_LINK_JOBS=4 \
  
      -DLLVM_ENABLE_UNWIND_TABLES=OFF \
  
+     -Wno-dev \
+ 
      ../llvm
  
      '
    - cmake --build . --target install
    - objdump -p $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} | egrep 'GLIBC_2\.(1[8-9]|[2-9][0-9])'
      && exit 1
    - objdump -p $DATADOG_AGENT_EMBEDDED_PATH/bin/llc | egrep 'GLIBC_2\.(1[8-9]|[2-9][0-9])'
      && exit 1
    - $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} -print-targets > clang_targets.txt
    - diff $CI_PROJECT_DIR/pkg/ebpf/c/expected_targets.txt clang_targets.txt
    - $DATADOG_AGENT_EMBEDDED_PATH/bin/llc --version | tail -n +7 > llc_targets.txt
    - diff $CI_PROJECT_DIR/pkg/ebpf/c/expected_targets.txt llc_targets.txt
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $S3_PERMANENT_ARTIFACTS_URI/clang-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/clang-${CLANG_MAJOR_VER}" "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +                             + + +                          +                                ++++++++++++++++++
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $S3_PERMANENT_ARTIFACTS_URI/llc-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llc" "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +        + + +                          +                              ++++++++++++++++++
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llvm-strip" "${S3_PERMANENT_ARTIFACTS_URI}/llvm-strip-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $S3_DD_AGENT_OMNIBUS_LLVM_URI/clang-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/clang-${CLANG_MAJOR_VER}" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/clang-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +                             + + +                            +                                ++++++++++++++++++
      --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $S3_DD_AGENT_OMNIBUS_LLVM_URI/llc-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llc" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/llc-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +        + + +                            +                              ++++++++++++++++++
+     --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llvm-strip" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/llvm-strip-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
      --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
    - mkdir -p $CI_PROJECT_DIR/.tmp
    - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $CI_PROJECT_DIR/.tmp/clang
    - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $CI_PROJECT_DIR/.tmp/llc
+   - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/llvm-strip $CI_PROJECT_DIR/.tmp/llvm-strip
    stage: deps_build
    timeout: 2h 00m
    variables:
+     BUILD_VERSION: v${CI_PIPELINE_ID}-${CI_COMMIT_SHORT_SHA}
+     CC: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-gcc
+     CMAKE_AR: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-ar
+     CMAKE_CXX_COMPILER: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-g++
+     CMAKE_C_COMPILER: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-gcc
+     CMAKE_FIND_ROOT_PATH: /opt/datadog/embedded
+     CMAKE_FIND_ROOT_PATH_MODE_PACKAGE: ONLY
+     CMAKE_RANLIB: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-ranlib
+     CMAKE_SYSTEM_NAME: Linux
+     CMAKE_SYSTEM_PROCESSOR: ${CMAKE_ARCH}
+     CXX: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-g++
      KUBERNETES_CPU_REQUEST: 4
+     KUBERNETES_MEMORY_LIMIT: 12Gi
+     KUBERNETES_MEMORY_REQUEST: 12Gi
.common_build_oci
  .common_build_oci:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    script:
    - echo "About to build for $RELEASE_VERSION"
    - AGENT_VERSION="$(dda inv agent.version -u)-1" || exit $?
    - export INSTALL_DIR=/opt/datadog-packages/datadog-agent/"$AGENT_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --host-distribution=ociru --install-directory="$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    variables:
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
.heroku_build_base
  .heroku_build_base:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-17-x64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - go_mod_tidy_check
    - build_system-probe-x64
    - go_deps
    - generate_minimized_btfs_x64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - echo "About to build for $RELEASE_VERSION"
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - set +x
    - printf -- "$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $DEB_GPG_KEY)" | gpg --import
      --batch
    - EXIT="${PIPESTATUS[0]}"; if [ $EXIT -ne 0 ]; then echo "Unable to locate credentials
      needs gitlab runner restart"; exit $EXIT; fi
    - DEB_SIGNING_PASSPHRASE=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $DEB_SIGNING_PASSPHRASE)
      || exit $?; export DEB_SIGNING_PASSPHRASE
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --flavor heroku
    - ls -la $OMNIBUS_PACKAGE_DIR
    - curl -sSL "https://dd-package-tools.s3.amazonaws.com/dd-pkg/${DD_PKG_VERSION}/dd-pkg_Linux_${DD_PKG_ARCH}.tar.gz"
      | tar -xz -C /usr/local/bin dd-pkg
    - dd-pkg version
    - find $OMNIBUS_PACKAGE_DIR -iregex '.*\.\(deb\|rpm\)' | xargs dd-pkg lint
    - "if [ -n \"$PACKAGE_REQUIRED_FILES_LIST\" ]; then\n  find $OMNIBUS_PACKAGE_DIR\
      \ \\( -name '*.deb' -or -name '*.rpm' \\) -a -not -name '*-dbg[_-]*' | xargs dd-pkg\
      \ check-files --required-files ${PACKAGE_REQUIRED_FILES_LIST}\nfi\n"
    - dd-pkg sign --key-id "${PIPELINE_KEY_ALIAS}" "${OMNIBUS_PACKAGE_DIR}"
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:amd64
    variables:
      DD_CC: x86_64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/x86_64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: x86_64-unknown-linux-gnu-g++
      DD_PKG_ARCH: x86_64
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: amd64
.prepare_secagent_ebpf_functional_tests
  .prepare_secagent_ebpf_functional_tests:
    artifacts:
      paths:
      - $CI_PROJECT_DIR/kmt-deps
      - $DD_AGENT_TESTING_DIR/site-cookbooks/dd-security-agent-check/files
      when: always
    before_script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache_tools.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache_tools.tar.xz
    - dda inv -e install-tools
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/bin
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/include
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.$ARCH /tmp/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.$ARCH /tmp/llc-bpf
?                                                                     ^^^^^^^^^^^^^
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
?      +         + + +                          +      +              +  +    ^^^^^^^^^^^^^^^^^^^^^^^^
+     /tmp/llc-bpf
    needs:
    - go_deps
    - go_tools_deps
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - dda inv -e kmt.prepare --ci --component="security-agent"
    - mkdir -p /opt/datadog-agent/embedded/bin
    - cp /tmp/clang-bpf /opt/datadog-agent/embedded/bin/clang-bpf
    - cp /tmp/llc-bpf /opt/datadog-agent/embedded/bin/llc-bpf
    stage: source_test
.prepare_sysprobe_ebpf_functional_tests
  .prepare_sysprobe_ebpf_functional_tests:
    artifacts:
      paths:
      - $CI_PROJECT_DIR/kmt-deps
      when: always
    before_script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache_tools.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache_tools.tar.xz
    - dda inv -e install-tools
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/bin
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/include
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.$ARCH /tmp/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.$ARCH /tmp/llc-bpf
?                                                                     ^^^^^^^^^^^^^
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
?      +         + + +                          +      +              +  +    ^^^^^^^^^^^^^^^^^^^^^^^^
+     /tmp/llc-bpf
    needs:
    - go_deps
    - go_tools_deps
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - dda inv -e kmt.prepare --ci --component="system-probe"
    stage: source_test
    variables:
      KUBERNETES_CPU_REQUEST: 4
.retrieve_sysprobe_deps
  .retrieve_sysprobe_deps:
  - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/bin
  - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/include
- - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.$ARCH /tmp/clang-bpf
- - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.$ARCH /tmp/llc-bpf
+ - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+   /tmp/clang-bpf
+ - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+   /tmp/llc-bpf
agent_heroku_deb-x64-a7
  agent_heroku_deb-x64-a7:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-17-x64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - go_mod_tidy_check
    - build_system-probe-x64
    - go_deps
    - generate_minimized_btfs_x64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - echo "About to build for $RELEASE_VERSION"
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - set +x
    - printf -- "$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $DEB_GPG_KEY)" | gpg --import
      --batch
    - EXIT="${PIPESTATUS[0]}"; if [ $EXIT -ne 0 ]; then echo "Unable to locate credentials
      needs gitlab runner restart"; exit $EXIT; fi
    - DEB_SIGNING_PASSPHRASE=$($CI_PROJECT_DIR/tools/ci/fetch_secret.sh $DEB_SIGNING_PASSPHRASE)
      || exit $?; export DEB_SIGNING_PASSPHRASE
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --flavor heroku
    - ls -la $OMNIBUS_PACKAGE_DIR
    - curl -sSL "https://dd-package-tools.s3.amazonaws.com/dd-pkg/${DD_PKG_VERSION}/dd-pkg_Linux_${DD_PKG_ARCH}.tar.gz"
      | tar -xz -C /usr/local/bin dd-pkg
    - dd-pkg version
    - find $OMNIBUS_PACKAGE_DIR -iregex '.*\.\(deb\|rpm\)' | xargs dd-pkg lint
    - "if [ -n \"$PACKAGE_REQUIRED_FILES_LIST\" ]; then\n  find $OMNIBUS_PACKAGE_DIR\
      \ \\( -name '*.deb' -or -name '*.rpm' \\) -a -not -name '*-dbg[_-]*' | xargs dd-pkg\
      \ check-files --required-files ${PACKAGE_REQUIRED_FILES_LIST}\nfi\n"
    - dd-pkg sign --key-id "${PIPELINE_KEY_ALIAS}" "${OMNIBUS_PACKAGE_DIR}"
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:amd64
    variables:
      DD_CC: x86_64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/x86_64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: x86_64-unknown-linux-gnu-g++
      DD_PKG_ARCH: x86_64
      DESTINATION_DBG_DEB: datadog-heroku-agent-dbg_7_amd64.deb
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: amd64
build_clang_arm64
  build_clang_arm64:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $CI_PROJECT_DIR/.tmp/clang
      - $CI_PROJECT_DIR/.tmp/llc
+     - $CI_PROJECT_DIR/.tmp/llvm-strip
-   image: registry.ddbuild.io/ci/datadog-agent-buildimages/system-probe_arm64$DATADOG_AGENT_SYSPROBE_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_SYSPROBE_BUILDIMAGES
?                                                           ^^^^^^ ^^^ ^^                   ---------                                   ---------
+   image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-23-arm64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
?                                                           ^^^^^ ^^^ ^^^^^^^
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - allow_failure: true
      when: manual
    script:
    - mkdir /tmp/clangbuild && cd /tmp/clangbuild
    - CLANG_MAJOR_VER=$(echo "${CLANG_LLVM_VER}" | cut -d '.' -f 1)
    - CLANG_SHA256SUM=6e912133bcf56e9cfe6a346fa7e5c52c2cde3e4e48b7a6cc6fcc7c75047da45f
    - LLVM_SHA256SUM=7d9a8405f557cefc5a21bf5672af73903b64749d9bc3a50322239f56f34ffddf
    - wget ${GENERAL_ARTIFACTS_CACHE_BUCKET_URL}/llvm/clang-${CLANG_LLVM_VER}.src.tar.xz
      -O clang.src.tar.xz
    - wget ${GENERAL_ARTIFACTS_CACHE_BUCKET_URL}/llvm/llvm-${CLANG_LLVM_VER}.src.tar.xz
      -O llvm.src.tar.xz
    - echo -e "${LLVM_SHA256SUM} llvm.src.tar.xz\n${CLANG_SHA256SUM} clang.src.tar.xz"
      | sha256sum --check -
    - mkdir clang && tar xf clang.src.tar.xz --strip-components=1 --no-same-owner -C
      clang
    - mkdir llvm && tar xf llvm.src.tar.xz --strip-components=1 --no-same-owner -C llvm
    - mkdir build && cd build
    - cp ../llvm/Modules/* ../llvm/cmake/modules || echo "LLVM common cmake utils not
      found in directory 'Modules'"
    - patch -ruN ../llvm/CMakeLists.txt < $CI_PROJECT_DIR/pkg/ebpf/c/cmakelists.patch
    - patch -ruN ../llvm/lib/Analysis/ConstantFolding.cpp < $CI_PROJECT_DIR/pkg/ebpf/c/constant_folding.patch
+   - 'cmake \
+ 
-   - 'cmake -DLLVM_ENABLE_PROJECTS=clang \
?   - ------
+     -DLLVM_ENABLE_PROJECTS=clang \
  
      -DLLVM_TARGETS_TO_BUILD="BPF" \
  
      -DCMAKE_INSTALL_PREFIX=$DATADOG_AGENT_EMBEDDED_PATH \
  
      -G "Ninja" \
  
      -DCMAKE_BUILD_TYPE=MinSizeRel \
+ 
+     -DCMAKE_SYSTEM_PROCESSOR=$CMAKE_SYSTEM_PROCESSOR \
+ 
+     -DCMAKE_SYSTEM_NAME=$CMAKE_SYSTEM_NAME \
+ 
+     -DCMAKE_RANLIB=$CMAKE_RANLIB \
+ 
+     -DCMAKE_AR=$CMAKE_AR \
+ 
+     -DCMAKE_C_COMPILER=$CMAKE_C_COMPILER \
+ 
+     -DCMAKE_CXX_COMPILER=$CMAKE_CXX_COMPILER \
+ 
+     -DCMAKE_FIND_ROOT_PATH=$CMAKE_FIND_ROOT_PATH \
+ 
+     -DCMAKE_FIND_ROOT_PATH_MODE_PACKAGE=$CMAKE_FIND_ROOT_PATH_MODE_PACKAGE \
  
      -DLLVM_BUILD_TOOLS=ON \
  
      -DLLVM_ENABLE_TERMINFO=OFF \
  
      -DLLVM_INCLUDE_EXAMPLES=OFF \
  
      -DLLVM_INCLUDE_TESTS=OFF \
  
      -DLLVM_INCLUDE_BENCHMARKS=OFF \
  
      -DLLVM_STATIC_LINK_CXX_STDLIB=ON \
  
      -DLLVM_ENABLE_BINDINGS=OFF \
  
      -DLLVM_PARALLEL_COMPILE_JOBS=4 \
  
      -DLLVM_PARALLEL_LINK_JOBS=4 \
  
      -DLLVM_ENABLE_UNWIND_TABLES=OFF \
  
+     -Wno-dev \
+ 
      ../llvm
  
      '
    - cmake --build . --target install
    - objdump -p $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} | egrep 'GLIBC_2\.(1[8-9]|[2-9][0-9])'
      && exit 1
    - objdump -p $DATADOG_AGENT_EMBEDDED_PATH/bin/llc | egrep 'GLIBC_2\.(1[8-9]|[2-9][0-9])'
      && exit 1
    - $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} -print-targets > clang_targets.txt
    - diff $CI_PROJECT_DIR/pkg/ebpf/c/expected_targets.txt clang_targets.txt
    - $DATADOG_AGENT_EMBEDDED_PATH/bin/llc --version | tail -n +7 > llc_targets.txt
    - diff $CI_PROJECT_DIR/pkg/ebpf/c/expected_targets.txt llc_targets.txt
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $S3_PERMANENT_ARTIFACTS_URI/clang-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/clang-${CLANG_MAJOR_VER}" "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +                             + + +                          +                                ++++++++++++++++++
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $S3_PERMANENT_ARTIFACTS_URI/llc-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llc" "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +        + + +                          +                              ++++++++++++++++++
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llvm-strip" "${S3_PERMANENT_ARTIFACTS_URI}/llvm-strip-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $S3_DD_AGENT_OMNIBUS_LLVM_URI/clang-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/clang-${CLANG_MAJOR_VER}" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/clang-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +                             + + +                            +                                ++++++++++++++++++
      --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $S3_DD_AGENT_OMNIBUS_LLVM_URI/llc-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llc" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/llc-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +        + + +                            +                              ++++++++++++++++++
+     --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llvm-strip" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/llvm-strip-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
      --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
    - mkdir -p $CI_PROJECT_DIR/.tmp
    - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $CI_PROJECT_DIR/.tmp/clang
    - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $CI_PROJECT_DIR/.tmp/llc
+   - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/llvm-strip $CI_PROJECT_DIR/.tmp/llvm-strip
    stage: deps_build
    tags:
    - arch:arm64
    timeout: 2h 00m
    variables:
      ARCH: arm64
+     BUILD_VERSION: v${CI_PIPELINE_ID}-${CI_COMMIT_SHORT_SHA}
+     CC: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-gcc
+     CMAKE_AR: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-ar
+     CMAKE_ARCH: aarch64
+     CMAKE_CXX_COMPILER: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-g++
+     CMAKE_C_COMPILER: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-gcc
+     CMAKE_FIND_ROOT_PATH: /opt/datadog/embedded
+     CMAKE_FIND_ROOT_PATH_MODE_PACKAGE: ONLY
+     CMAKE_RANLIB: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-ranlib
+     CMAKE_SYSTEM_NAME: Linux
+     CMAKE_SYSTEM_PROCESSOR: ${CMAKE_ARCH}
+     CXX: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-g++
      KUBERNETES_CPU_REQUEST: 4
+     KUBERNETES_MEMORY_LIMIT: 12Gi
+     KUBERNETES_MEMORY_REQUEST: 12Gi
build_clang_x64
  build_clang_x64:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $CI_PROJECT_DIR/.tmp/clang
      - $CI_PROJECT_DIR/.tmp/llc
+     - $CI_PROJECT_DIR/.tmp/llvm-strip
-   image: registry.ddbuild.io/ci/datadog-agent-buildimages/system-probe_x64$DATADOG_AGENT_SYSPROBE_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_SYSPROBE_BUILDIMAGES
?                                                           ^^^^^^ ^^^ ^^                 ---------                                   ---------
+   image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-17-x64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
?                                                           ^^^^^ ^^^ ^^^^^^^
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - allow_failure: true
      when: manual
    script:
    - mkdir /tmp/clangbuild && cd /tmp/clangbuild
    - CLANG_MAJOR_VER=$(echo "${CLANG_LLVM_VER}" | cut -d '.' -f 1)
    - CLANG_SHA256SUM=6e912133bcf56e9cfe6a346fa7e5c52c2cde3e4e48b7a6cc6fcc7c75047da45f
    - LLVM_SHA256SUM=7d9a8405f557cefc5a21bf5672af73903b64749d9bc3a50322239f56f34ffddf
    - wget ${GENERAL_ARTIFACTS_CACHE_BUCKET_URL}/llvm/clang-${CLANG_LLVM_VER}.src.tar.xz
      -O clang.src.tar.xz
    - wget ${GENERAL_ARTIFACTS_CACHE_BUCKET_URL}/llvm/llvm-${CLANG_LLVM_VER}.src.tar.xz
      -O llvm.src.tar.xz
    - echo -e "${LLVM_SHA256SUM} llvm.src.tar.xz\n${CLANG_SHA256SUM} clang.src.tar.xz"
      | sha256sum --check -
    - mkdir clang && tar xf clang.src.tar.xz --strip-components=1 --no-same-owner -C
      clang
    - mkdir llvm && tar xf llvm.src.tar.xz --strip-components=1 --no-same-owner -C llvm
    - mkdir build && cd build
    - cp ../llvm/Modules/* ../llvm/cmake/modules || echo "LLVM common cmake utils not
      found in directory 'Modules'"
    - patch -ruN ../llvm/CMakeLists.txt < $CI_PROJECT_DIR/pkg/ebpf/c/cmakelists.patch
    - patch -ruN ../llvm/lib/Analysis/ConstantFolding.cpp < $CI_PROJECT_DIR/pkg/ebpf/c/constant_folding.patch
+   - 'cmake \
+ 
-   - 'cmake -DLLVM_ENABLE_PROJECTS=clang \
?   - ------
+     -DLLVM_ENABLE_PROJECTS=clang \
  
      -DLLVM_TARGETS_TO_BUILD="BPF" \
  
      -DCMAKE_INSTALL_PREFIX=$DATADOG_AGENT_EMBEDDED_PATH \
  
      -G "Ninja" \
  
      -DCMAKE_BUILD_TYPE=MinSizeRel \
+ 
+     -DCMAKE_SYSTEM_PROCESSOR=$CMAKE_SYSTEM_PROCESSOR \
+ 
+     -DCMAKE_SYSTEM_NAME=$CMAKE_SYSTEM_NAME \
+ 
+     -DCMAKE_RANLIB=$CMAKE_RANLIB \
+ 
+     -DCMAKE_AR=$CMAKE_AR \
+ 
+     -DCMAKE_C_COMPILER=$CMAKE_C_COMPILER \
+ 
+     -DCMAKE_CXX_COMPILER=$CMAKE_CXX_COMPILER \
+ 
+     -DCMAKE_FIND_ROOT_PATH=$CMAKE_FIND_ROOT_PATH \
+ 
+     -DCMAKE_FIND_ROOT_PATH_MODE_PACKAGE=$CMAKE_FIND_ROOT_PATH_MODE_PACKAGE \
  
      -DLLVM_BUILD_TOOLS=ON \
  
      -DLLVM_ENABLE_TERMINFO=OFF \
  
      -DLLVM_INCLUDE_EXAMPLES=OFF \
  
      -DLLVM_INCLUDE_TESTS=OFF \
  
      -DLLVM_INCLUDE_BENCHMARKS=OFF \
  
      -DLLVM_STATIC_LINK_CXX_STDLIB=ON \
  
      -DLLVM_ENABLE_BINDINGS=OFF \
  
      -DLLVM_PARALLEL_COMPILE_JOBS=4 \
  
      -DLLVM_PARALLEL_LINK_JOBS=4 \
  
      -DLLVM_ENABLE_UNWIND_TABLES=OFF \
  
+     -Wno-dev \
+ 
      ../llvm
  
      '
    - cmake --build . --target install
    - objdump -p $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} | egrep 'GLIBC_2\.(1[8-9]|[2-9][0-9])'
      && exit 1
    - objdump -p $DATADOG_AGENT_EMBEDDED_PATH/bin/llc | egrep 'GLIBC_2\.(1[8-9]|[2-9][0-9])'
      && exit 1
    - $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} -print-targets > clang_targets.txt
    - diff $CI_PROJECT_DIR/pkg/ebpf/c/expected_targets.txt clang_targets.txt
    - $DATADOG_AGENT_EMBEDDED_PATH/bin/llc --version | tail -n +7 > llc_targets.txt
    - diff $CI_PROJECT_DIR/pkg/ebpf/c/expected_targets.txt llc_targets.txt
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $S3_PERMANENT_ARTIFACTS_URI/clang-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/clang-${CLANG_MAJOR_VER}" "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +                             + + +                          +                                ++++++++++++++++++
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $S3_PERMANENT_ARTIFACTS_URI/llc-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llc" "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +        + + +                          +                              ++++++++++++++++++
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llvm-strip" "${S3_PERMANENT_ARTIFACTS_URI}/llvm-strip-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $S3_DD_AGENT_OMNIBUS_LLVM_URI/clang-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/clang-${CLANG_MAJOR_VER}" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/clang-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +                             + + +                            +                                ++++++++++++++++++
      --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
-   - $S3_CP_CMD $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $S3_DD_AGENT_OMNIBUS_LLVM_URI/llc-${CLANG_LLVM_VER}.${ARCH}
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llc" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/llc-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
?      +         + + +                           +        + + +                            +                              ++++++++++++++++++
+     --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
+   - ${S3_CP_CMD} "${DATADOG_AGENT_EMBEDDED_PATH}/bin/llvm-strip" "${S3_DD_AGENT_OMNIBUS_LLVM_URI}/llvm-strip-${CLANG_LLVM_VER}.${ARCH}.${BUILD_VERSION}"
      --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
    - mkdir -p $CI_PROJECT_DIR/.tmp
    - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/clang-${CLANG_MAJOR_VER} $CI_PROJECT_DIR/.tmp/clang
    - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/llc $CI_PROJECT_DIR/.tmp/llc
+   - cp $DATADOG_AGENT_EMBEDDED_PATH/bin/llvm-strip $CI_PROJECT_DIR/.tmp/llvm-strip
    stage: deps_build
    tags:
    - arch:amd64
    timeout: 2h 00m
    variables:
      ARCH: amd64
+     BUILD_VERSION: v${CI_PIPELINE_ID}-${CI_COMMIT_SHORT_SHA}
+     CC: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-gcc
+     CMAKE_AR: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-ar
+     CMAKE_ARCH: x86_64
+     CMAKE_CXX_COMPILER: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-g++
+     CMAKE_C_COMPILER: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-gcc
+     CMAKE_FIND_ROOT_PATH: /opt/datadog/embedded
+     CMAKE_FIND_ROOT_PATH_MODE_PACKAGE: ONLY
+     CMAKE_RANLIB: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-ranlib
+     CMAKE_SYSTEM_NAME: Linux
+     CMAKE_SYSTEM_PROCESSOR: ${CMAKE_ARCH}
+     CXX: /opt/toolchains/${CMAKE_ARCH}/bin/${CMAKE_ARCH}-unknown-linux-gnu-g++
      KUBERNETES_CPU_REQUEST: 4
+     KUBERNETES_MEMORY_LIMIT: 12Gi
+     KUBERNETES_MEMORY_REQUEST: 12Gi
datadog-agent-7-arm64
  datadog-agent-7-arm64:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-23-arm64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - build_system-probe-arm64
    - go_deps
    - generate_minimized_btfs_arm64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - echo "About to build for $RELEASE_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --flavor "$FLAVOR" --config-directory "$CONFIG_DIR" --install-directory "$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:arm64
    variables:
      DD_CC: aarch64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/aarch64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: aarch64-unknown-linux-gnu-g++
      FLAVOR: base
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: arm64
datadog-agent-7-arm64-fips
  datadog-agent-7-arm64-fips:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-23-arm64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - build_system-probe-arm64
    - go_deps
    - generate_minimized_btfs_arm64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - echo "About to build for $RELEASE_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --flavor "$FLAVOR" --config-directory "$CONFIG_DIR" --install-directory "$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:arm64
    variables:
      DD_CC: aarch64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/aarch64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: aarch64-unknown-linux-gnu-g++
      FLAVOR: fips
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: arm64
datadog-agent-7-x64
  datadog-agent-7-x64:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-17-x64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - build_system-probe-x64
    - go_deps
    - generate_minimized_btfs_x64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - echo "About to build for $RELEASE_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --flavor "$FLAVOR" --config-directory "$CONFIG_DIR" --install-directory "$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:amd64
    variables:
      DD_CC: x86_64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/x86_64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: x86_64-unknown-linux-gnu-g++
      FLAVOR: base
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: amd64
datadog-agent-7-x64-fips
  datadog-agent-7-x64-fips:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-17-x64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - build_system-probe-x64
    - go_deps
    - generate_minimized_btfs_x64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - echo "About to build for $RELEASE_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --flavor "$FLAVOR" --config-directory "$CONFIG_DIR" --install-directory "$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:amd64
    variables:
      DD_CC: x86_64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/x86_64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: x86_64-unknown-linux-gnu-g++
      FLAVOR: fips
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: amd64
datadog-agent-oci-arm64-a7
  datadog-agent-oci-arm64-a7:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-23-arm64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - go_mod_tidy_check
    - build_system-probe-arm64
    - go_deps
    - generate_minimized_btfs_arm64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - echo "About to build for $RELEASE_VERSION"
    - AGENT_VERSION="$(dda inv agent.version -u)-1" || exit $?
    - export INSTALL_DIR=/opt/datadog-packages/datadog-agent/"$AGENT_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --host-distribution=ociru --install-directory="$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:arm64
    variables:
      DD_CC: aarch64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/aarch64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: aarch64-unknown-linux-gnu-g++
      DESTINATION_OCI: datadog-agent-7-remote-updater-arm64.tar.xz
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: arm64
datadog-agent-oci-x64-a7
  datadog-agent-oci-x64-a7:
    artifacts:
      expire_in: 2 weeks
      paths:
      - $OMNIBUS_PACKAGE_DIR
    cache:
    - key:
        files:
        - omnibus/Gemfile
        - release.json
        prefix: omnibus-deps-$CI_JOB_NAME-$OMNIBUS_RUBY_VERSION
      paths:
      - omnibus/vendor/bundle
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/linux-glibc-2-17-x64$DATADOG_AGENT_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_BUILDIMAGES
    needs:
    - go_mod_tidy_check
    - build_system-probe-x64
    - go_deps
    - generate_minimized_btfs_x64
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - echo "About to build for $RELEASE_VERSION"
    - AGENT_VERSION="$(dda inv agent.version -u)-1" || exit $?
    - export INSTALL_DIR=/opt/datadog-packages/datadog-agent/"$AGENT_VERSION"
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - pushd omnibus && bundle config set --local path 'vendor/bundle' && popd
    - rm -rf $OMNIBUS_PACKAGE_DIR/*
    - tar -xf $CI_PROJECT_DIR/sysprobe-build-outputs.tar.xz
    - mkdir -p /tmp/system-probe
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.${PACKAGE_ARCH} /tmp/system-probe/llc-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${PACKAGE_ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/system-probe/llc-bpf
    - cp $CI_PROJECT_DIR/minimized-btfs.tar.xz /tmp/system-probe/minimized-btfs.tar.xz
    - chmod 0744 /tmp/system-probe/clang-bpf /tmp/system-probe/llc-bpf
    - dda inv -e omnibus.build --release-version "$RELEASE_VERSION" --base-dir $OMNIBUS_BASE_DIR
      --skip-deps --go-mod-cache="$GOPATH/pkg/mod" --system-probe-bin=/tmp/system-probe
      --host-distribution=ociru --install-directory="$INSTALL_DIR"
    - ls -la $OMNIBUS_PACKAGE_DIR
    - $S3_CP_CMD $OMNIBUS_PACKAGE_DIR/version-manifest.json $S3_SBOM_STORAGE_URI/$CI_JOB_NAME/version-manifest.json
    stage: package_build
    tags:
    - arch:amd64
    variables:
      DD_CC: x86_64-unknown-linux-gnu-gcc
      DD_CMAKE_TOOLCHAIN: /opt/cmake/x86_64-unknown-linux-gnu.toolchain.cmake
      DD_CXX: x86_64-unknown-linux-gnu-g++
      DESTINATION_OCI: datadog-agent-7-remote-updater-amd64.tar.xz
      KUBERNETES_CPU_REQUEST: 16
      KUBERNETES_MEMORY_LIMIT: 32Gi
      KUBERNETES_MEMORY_REQUEST: 32Gi
      PACKAGE_ARCH: amd64
prepare_secagent_ebpf_functional_tests_arm64
  prepare_secagent_ebpf_functional_tests_arm64:
    artifacts:
      paths:
      - $CI_PROJECT_DIR/kmt-deps
      - $DD_AGENT_TESTING_DIR/site-cookbooks/dd-security-agent-check/files
      when: always
    before_script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache_tools.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache_tools.tar.xz
    - dda inv -e install-tools
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/bin
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/include
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.$ARCH /tmp/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.$ARCH /tmp/llc-bpf
?                                                                     ^^^^^^^^^^^^^
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
?      +         + + +                          +      +              +  +    ^^^^^^^^^^^^^^^^^^^^^^^^
+     /tmp/llc-bpf
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/system-probe_arm64$DATADOG_AGENT_SYSPROBE_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_SYSPROBE_BUILDIMAGES
    needs:
    - go_deps
    - go_tools_deps
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - dda inv -e kmt.prepare --ci --component="security-agent"
    - mkdir -p /opt/datadog-agent/embedded/bin
    - cp /tmp/clang-bpf /opt/datadog-agent/embedded/bin/clang-bpf
    - cp /tmp/llc-bpf /opt/datadog-agent/embedded/bin/llc-bpf
    stage: source_test
    tags:
    - arch:arm64
    variables:
      ARCH: arm64
prepare_secagent_ebpf_functional_tests_x64
  prepare_secagent_ebpf_functional_tests_x64:
    artifacts:
      paths:
      - $CI_PROJECT_DIR/kmt-deps
      - $DD_AGENT_TESTING_DIR/site-cookbooks/dd-security-agent-check/files
      when: always
    before_script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache_tools.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache_tools.tar.xz
    - dda inv -e install-tools
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/bin
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/include
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.$ARCH /tmp/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.$ARCH /tmp/llc-bpf
?                                                                     ^^^^^^^^^^^^^
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
?      +         + + +                          +      +              +  +    ^^^^^^^^^^^^^^^^^^^^^^^^
+     /tmp/llc-bpf
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/system-probe_x64$DATADOG_AGENT_SYSPROBE_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_SYSPROBE_BUILDIMAGES
    needs:
    - go_deps
    - go_tools_deps
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - dda inv -e kmt.prepare --ci --component="security-agent"
    - mkdir -p /opt/datadog-agent/embedded/bin
    - cp /tmp/clang-bpf /opt/datadog-agent/embedded/bin/clang-bpf
    - cp /tmp/llc-bpf /opt/datadog-agent/embedded/bin/llc-bpf
    stage: source_test
    tags:
    - arch:amd64
    variables:
      ARCH: amd64
prepare_sysprobe_ebpf_functional_tests_arm64
  prepare_sysprobe_ebpf_functional_tests_arm64:
    artifacts:
      paths:
      - $CI_PROJECT_DIR/kmt-deps
      when: always
    before_script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache_tools.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache_tools.tar.xz
    - dda inv -e install-tools
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/bin
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/include
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.$ARCH /tmp/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.$ARCH /tmp/llc-bpf
?                                                                     ^^^^^^^^^^^^^
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
?      +         + + +                          +      +              +  +    ^^^^^^^^^^^^^^^^^^^^^^^^
+     /tmp/llc-bpf
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/system-probe_arm64$DATADOG_AGENT_SYSPROBE_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_SYSPROBE_BUILDIMAGES
    needs:
    - go_deps
    - go_tools_deps
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - dda inv -e kmt.prepare --ci --component="system-probe"
    stage: source_test
    tags:
    - arch:arm64
    variables:
      ARCH: arm64
      KUBERNETES_CPU_REQUEST: 4
prepare_sysprobe_ebpf_functional_tests_x64
  prepare_sysprobe_ebpf_functional_tests_x64:
    artifacts:
      paths:
      - $CI_PROJECT_DIR/kmt-deps
      when: always
    before_script:
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache.tar.xz
    - mkdir -p $GOPATH/pkg/mod/cache && tar xJf modcache_tools.tar.xz -C $GOPATH/pkg/mod/cache
      || exit 101
    - rm -f modcache_tools.tar.xz
    - dda inv -e install-tools
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/bin
    - mkdir -p $DATADOG_AGENT_EMBEDDED_PATH/include
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/clang-$CLANG_LLVM_VER.$ARCH /tmp/clang-bpf
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/clang-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
+     /tmp/clang-bpf
-   - $S3_CP_CMD $S3_PERMANENT_ARTIFACTS_URI/llc-$CLANG_LLVM_VER.$ARCH /tmp/llc-bpf
?                                                                     ^^^^^^^^^^^^^
+   - ${S3_CP_CMD} "${S3_PERMANENT_ARTIFACTS_URI}/llc-${CLANG_LLVM_VER}.${ARCH}${CLANG_BUILD_VERSION}"
?      +         + + +                          +      +              +  +    ^^^^^^^^^^^^^^^^^^^^^^^^
+     /tmp/llc-bpf
    image: registry.ddbuild.io/ci/datadog-agent-buildimages/system-probe_x64$DATADOG_AGENT_SYSPROBE_BUILDIMAGES_SUFFIX:$DATADOG_AGENT_SYSPROBE_BUILDIMAGES
    needs:
    - go_deps
    - go_tools_deps
    rules:
    - if: $CI_COMMIT_BRANCH =~ /^mq-working-branch-/
      when: never
    - when: on_success
    script:
    - dda inv -e kmt.prepare --ci --component="system-probe"
    stage: source_test
    tags:
    - arch:amd64
    variables:
      ARCH: amd64
      KUBERNETES_CPU_REQUEST: 4

Changes Summary

Removed Modified Added Renamed
0 22 0 0

ℹ️ Diff available in the job log.

@agent-platform-auto-pr
Copy link
Contributor

Uncompressed package size comparison

Comparison with ancestor 38b97cbaf2d3451e2d0d58312af9211203877e64

Diff per package
package diff status size ancestor threshold
datadog-agent-amd64-deb 0.00MB 807.23MB 807.23MB 0.50MB
datadog-agent-x86_64-rpm 0.00MB 817.08MB 817.08MB 0.50MB
datadog-agent-x86_64-suse 0.00MB 817.08MB 817.08MB 0.50MB
datadog-agent-aarch64-rpm 0.00MB 808.06MB 808.06MB 0.50MB
datadog-agent-arm64-deb 0.00MB 798.24MB 798.24MB 0.50MB
datadog-dogstatsd-amd64-deb 0.00MB 39.49MB 39.49MB 0.50MB
datadog-dogstatsd-x86_64-rpm 0.00MB 39.57MB 39.57MB 0.50MB
datadog-dogstatsd-x86_64-suse 0.00MB 39.57MB 39.57MB 0.50MB
datadog-dogstatsd-arm64-deb 0.00MB 38.01MB 38.01MB 0.50MB
datadog-heroku-agent-amd64-deb 0.00MB 442.24MB 442.24MB 0.50MB
datadog-iot-agent-amd64-deb 0.00MB 61.10MB 61.10MB 0.50MB
datadog-iot-agent-x86_64-rpm 0.00MB 61.18MB 61.18MB 0.50MB
datadog-iot-agent-x86_64-suse 0.00MB 61.17MB 61.17MB 0.50MB
datadog-iot-agent-arm64-deb 0.00MB 58.39MB 58.39MB 0.50MB
datadog-iot-agent-aarch64-rpm 0.00MB 58.46MB 58.46MB 0.50MB

Decision

✅ Passed

Copy link

Regression Detector

Regression Detector Results

Metrics dashboard
Target profiles
Run ID: c4ae8269-9349-404b-8d57-3ee8330ed44d

Baseline: 38b97cb
Comparison: e3a91d3
Diff

Optimization Goals: ✅ No significant changes detected

Fine details of change detection per experiment

perf experiment goal Δ mean % Δ mean % CI trials links
uds_dogstatsd_to_api_cpu % cpu utilization +2.57 [+1.68, +3.45] 1 Logs
otlp_ingest_traces memory utilization +2.15 [+1.76, +2.54] 1 Logs
tcp_syslog_to_blackhole ingress throughput +1.10 [+1.03, +1.16] 1 Logs
quality_gate_logs % cpu utilization +0.49 [-2.30, +3.28] 1 Logs
quality_gate_idle memory utilization +0.10 [+0.02, +0.18] 1 Logs bounds checks dashboard
file_to_blackhole_300ms_latency egress throughput +0.03 [-0.60, +0.66] 1 Logs
tcp_dd_logs_filter_exclude ingress throughput +0.00 [-0.01, +0.02] 1 Logs
uds_dogstatsd_to_api ingress throughput -0.00 [-0.28, +0.28] 1 Logs
file_to_blackhole_0ms_latency_http2 egress throughput -0.01 [-0.75, +0.73] 1 Logs
file_to_blackhole_0ms_latency_http1 egress throughput -0.02 [-0.81, +0.77] 1 Logs
file_to_blackhole_0ms_latency egress throughput -0.03 [-0.76, +0.71] 1 Logs
file_to_blackhole_100ms_latency egress throughput -0.05 [-0.76, +0.67] 1 Logs
file_to_blackhole_1000ms_latency egress throughput -0.08 [-0.84, +0.68] 1 Logs
file_to_blackhole_500ms_latency egress throughput -0.13 [-0.92, +0.67] 1 Logs
file_to_blackhole_1000ms_latency_linear_load egress throughput -0.23 [-0.70, +0.24] 1 Logs
file_tree memory utilization -0.24 [-0.46, -0.02] 1 Logs
otlp_ingest_logs memory utilization -0.27 [-0.43, -0.11] 1 Logs
quality_gate_idle_all_features memory utilization -0.37 [-0.50, -0.25] 1 Logs bounds checks dashboard
uds_dogstatsd_20mb_12k_contexts_20_senders memory utilization -0.50 [-0.56, -0.44] 1 Logs
otlp_ingest_metrics memory utilization -0.55 [-0.70, -0.40] 1 Logs

Bounds Checks: ✅ Passed

perf experiment bounds_check_name replicates_passed links
file_to_blackhole_0ms_latency lost_bytes 10/10
file_to_blackhole_0ms_latency memory_usage 10/10
file_to_blackhole_0ms_latency_http1 lost_bytes 10/10
file_to_blackhole_0ms_latency_http1 memory_usage 10/10
file_to_blackhole_0ms_latency_http2 lost_bytes 10/10
file_to_blackhole_0ms_latency_http2 memory_usage 10/10
file_to_blackhole_1000ms_latency memory_usage 10/10
file_to_blackhole_1000ms_latency_linear_load memory_usage 10/10
file_to_blackhole_100ms_latency lost_bytes 10/10
file_to_blackhole_100ms_latency memory_usage 10/10
file_to_blackhole_300ms_latency lost_bytes 10/10
file_to_blackhole_300ms_latency memory_usage 10/10
file_to_blackhole_500ms_latency lost_bytes 10/10
file_to_blackhole_500ms_latency memory_usage 10/10
quality_gate_idle intake_connections 10/10 bounds checks dashboard
quality_gate_idle memory_usage 10/10 bounds checks dashboard
quality_gate_idle_all_features intake_connections 10/10 bounds checks dashboard
quality_gate_idle_all_features memory_usage 10/10 bounds checks dashboard
quality_gate_logs intake_connections 10/10
quality_gate_logs lost_bytes 10/10
quality_gate_logs memory_usage 10/10

Explanation

Confidence level: 90.00%
Effect size tolerance: |Δ mean %| ≥ 5.00%

Performance changes are noted in the perf column of each table:

  • ✅ = significantly better comparison variant performance
  • ❌ = significantly worse comparison variant performance
  • ➖ = no significant change in performance

A regression test is an A/B test of target performance in a repeatable rig, where "performance" is measured as "comparison variant minus baseline variant" for an optimization goal (e.g., ingress throughput). Due to intrinsic variability in measuring that goal, we can only estimate its mean value for each experiment; we report uncertainty in that value as a 90.00% confidence interval denoted "Δ mean % CI".

For each experiment, we decide whether a change in performance is a "regression" -- a change worth investigating further -- if all of the following criteria are true:

  1. Its estimated |Δ mean %| ≥ 5.00%, indicating the change is big enough to merit a closer look.

  2. Its 90.00% confidence interval "Δ mean % CI" does not contain zero, indicating that if our statistical model is accurate, there is at least a 90.00% chance there is a difference in performance between baseline and comparison variants.

  3. Its configuration does not mark it "erratic".

CI Pass/Fail Decision

Passed. All Quality Gates passed.

  • quality_gate_logs, bounds check lost_bytes: 10/10 replicas passed. Gate passed.
  • quality_gate_logs, bounds check intake_connections: 10/10 replicas passed. Gate passed.
  • quality_gate_logs, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_idle_all_features, bounds check intake_connections: 10/10 replicas passed. Gate passed.
  • quality_gate_idle_all_features, bounds check memory_usage: 10/10 replicas passed. Gate passed.
  • quality_gate_idle, bounds check intake_connections: 10/10 replicas passed. Gate passed.
  • quality_gate_idle, bounds check memory_usage: 10/10 replicas passed. Gate passed.

@agent-platform-auto-pr
Copy link
Contributor

Static quality checks ✅

Please find below the results from static quality gates

Successful checks

Info

Result Quality gate On disk size On disk size limit On wire size On wire size limit
static_quality_gate_agent_deb_amd64 781.46 MiB 781.68 MiB 190.71 MiB 191.21 MiB
static_quality_gate_agent_deb_amd64_fips 779.49 MiB 779.64 MiB 190.09 MiB 190.66 MiB
static_quality_gate_agent_rpm_amd64 781.51 MiB 781.68 MiB 193.18 MiB 193.7 MiB
static_quality_gate_agent_rpm_amd64_fips 779.48 MiB 779.78 MiB 192.6 MiB 193.02 MiB
static_quality_gate_agent_rpm_arm64 772.89 MiB 773.19 MiB 174.27 MiB 174.7 MiB
static_quality_gate_agent_rpm_arm64_fips 771.07 MiB 771.33 MiB 173.44 MiB 173.92 MiB
static_quality_gate_agent_suse_amd64 781.47 MiB 781.76 MiB 193.18 MiB 193.7 MiB
static_quality_gate_agent_suse_arm64 772.9 MiB 773.22 MiB 174.27 MiB 174.7 MiB
static_quality_gate_agent_suse_amd64_fips 779.47 MiB 779.77 MiB 192.6 MiB 193.02 MiB
static_quality_gate_agent_suse_arm64_fips 771.07 MiB 771.34 MiB 173.44 MiB 173.92 MiB
static_quality_gate_agent_msi 980.61 MiB 980.98 MiB 149.61 MiB 150.11 MiB
static_quality_gate_agent_heroku_amd64 429.84 MiB 430.25 MiB 112.61 MiB 113.11 MiB
static_quality_gate_dogstatsd_deb_amd64 37.74 MiB 38.23 MiB 9.78 MiB 10.28 MiB
static_quality_gate_dogstatsd_deb_arm64 36.33 MiB 36.82 MiB 8.48 MiB 8.98 MiB
static_quality_gate_dogstatsd_rpm_amd64 37.74 MiB 38.23 MiB 9.79 MiB 10.29 MiB
static_quality_gate_dogstatsd_suse_amd64 37.74 MiB 38.23 MiB 9.79 MiB 10.29 MiB
static_quality_gate_iot_agent_deb_amd64 58.35 MiB 58.84 MiB 14.74 MiB 15.24 MiB
static_quality_gate_iot_agent_deb_arm64 55.77 MiB 56.26 MiB 12.73 MiB 13.23 MiB
static_quality_gate_iot_agent_deb_armhf 54.44 MiB 54.93 MiB 12.73 MiB 13.23 MiB
static_quality_gate_iot_agent_rpm_amd64 58.35 MiB 58.84 MiB 14.76 MiB 15.26 MiB
static_quality_gate_iot_agent_rpm_arm64 55.77 MiB 56.26 MiB 12.75 MiB 13.25 MiB
static_quality_gate_iot_agent_rpm_armhf 54.44 MiB 54.93 MiB 12.74 MiB 13.24 MiB
static_quality_gate_iot_agent_suse_amd64 58.35 MiB 58.84 MiB 14.76 MiB 15.26 MiB
static_quality_gate_docker_agent_amd64 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_arm64 880.72 MiB 881.08 MiB 277.84 MiB 278.3 MiB
static_quality_gate_docker_agent_jmx_amd64 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_jmx_arm64 880.72 MiB 881.08 MiB 277.84 MiB 278.3 MiB
static_quality_gate_docker_agent_windows1809 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_windows1809_core 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_windows1809_core_jmx 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_windows1809_jmx 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_windows2022 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_windows2022_core 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_windows2022_core_jmx 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_agent_windows2022_jmx 866.04 MiB 866.39 MiB 291.37 MiB 291.84 MiB
static_quality_gate_docker_dogstatsd_amd64 45.88 MiB 46.37 MiB 17.3 MiB 17.8 MiB
static_quality_gate_docker_dogstatsd_arm64 44.5 MiB 44.99 MiB 16.17 MiB 16.66 MiB
static_quality_gate_docker_cluster_agent_amd64 262.94 MiB 263.29 MiB 105.59 MiB 106.03 MiB
static_quality_gate_docker_cluster_agent_arm64 278.9 MiB 279.25 MiB 100.45 MiB 100.87 MiB
static_quality_gate_docker_cws_instrumentation_amd64 6.65 MiB 7.15 MiB 2.82 MiB 3.32 MiB
static_quality_gate_docker_cws_instrumentation_arm64 6.44 MiB 6.94 MiB 2.6 MiB 3.1 MiB

@brycekahle
Copy link
Member Author

/merge

@dd-devflow
Copy link

dd-devflow bot commented Mar 28, 2025

View all feedbacks in Devflow UI.
2025-03-28 20:09:54 UTC ℹ️ Start processing command /merge


2025-03-28 20:10:03 UTC ℹ️ MergeQueue: pull request added to the queue

The expected merge time in main is approximately 43m (p90).


2025-03-28 20:41:21 UTC ℹ️ MergeQueue: This merge request was merged

@dd-mergequeue dd-mergequeue bot merged commit ee70de7 into main Mar 28, 2025
389 checks passed
@dd-mergequeue dd-mergequeue bot deleted the bryce.kahle/clang-glibc-build branch March 28, 2025 20:41
@github-actions github-actions bot added this to the 7.66.0 milestone Mar 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
ask-review Ask required teams to review this PR changelog/no-changelog component/system-probe medium review PR review might take time qa/done QA done before merge and regressions are covered by tests team/ebpf-platform
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants