-
Notifications
You must be signed in to change notification settings - Fork 0
135 lines (120 loc) · 5.32 KB
/
Copy pathkernel.yml
File metadata and controls
135 lines (120 loc) · 5.32 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
name: Kernel
# The guest kernel, for the same reason QEMU has its own workflow: compiling it is tens of
# minutes and the merge gate must not wait for it.
#
# It matters more than a build time, though. A changed kernel is a changed machine — the
# fingerprint hashes this binary by content — so every checkpoint taken against the previous
# one stops resuming. The job prints the checksum of what it produced for exactly that
# reason: a config change whose effect nobody looked at is a fleet-wide event nobody
# noticed.
on:
# kernel/**, and versions.yaml when it moves the kernel or its toolchain; see the note in
# qemu.yml.
push:
branches: [main]
paths:
- kernel/**
- versions.yaml
- go.mod
- .github/workflows/kernel.yml
pull_request:
paths:
- kernel/**
- versions.yaml
- go.mod
- .github/workflows/kernel.yml
workflow_dispatch:
permissions:
contents: read
concurrency:
group: kernel-${{ github.head_ref || github.ref_name }}
# Never on main: a cancelled run there is a commit nobody proved.
cancel-in-progress: ${{ github.ref_name != 'main' }}
jobs:
# Whether this change can reach the kernel; see the note in qemu.yml.
changed:
runs-on: blacksmith-8vcpu-ubuntu-2404
timeout-minutes: 10
outputs:
build: ${{ steps.touches.outputs.build }}
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
fetch-depth: 0
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Does the change reach the kernel
id: touches
env:
BASE: ${{ github.event.pull_request.base.sha || github.event.before }}
run: |
build=$(hack/touches "$BASE" debian debian-snapshot kernel moby-check-config -- \
kernel go.mod .github/workflows/kernel.yml)
echo "build=${build}" | tee -a "$GITHUB_OUTPUT"
build:
needs: changed
if: needs.changed.outputs.build == 'true'
runs-on: blacksmith-8vcpu-ubuntu-2404
timeout-minutes: 180
steps:
- name: Checkout
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
# The Taskfile hands the build its pins with `go tool versions`.
- name: Set up Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7.0.0
with:
go-version-file: go.mod
cache: true
- name: Set up Task
uses: go-task/setup-task@a00fbb05ce67b35648be3c78cbc9fd85354c757e # v2.2.0
# One sticky disk per thing built, and no silent fallback; see the note in qemu.yml.
- name: Setup Blacksmith Builder
uses: useblacksmith/setup-docker-builder@19215110ab936351210feebdfa5b440b4493e184 # v2.2.0
with:
cache-key: spin-machine/kernel
nofallback: true
# Without this, `--cache-to type=gha` below is a silent no-op: the tokens BuildKit
# needs reach JavaScript actions and not `run:` steps. See the long note in qemu.yml.
- name: Expose the Actions cache to buildx
uses: crazy-max/ghaction-github-runtime@04d248b84655b509d8c44dc1d6f990c879747487 # v4.0.0
# Ends in `task kernel:verify`, which opens the ELF and checks the Xen PVH notes
# survived the strip. Without them QEMU has no entry point into this kernel and the
# failure is a VM that does not start, in whichever lane boots one next.
- name: Build the kernel
run: |
CACHE_EXPORT=${{ github.event_name == 'push' && github.ref == 'refs/heads/main' }} CACHE_BACKEND=gha task kernel:build KERNEL_NPROC=4
# Compared against the last released machine, which every release publishes as a
# machine.env asset. The kernel's checksum is one of the numbers in it that decide
# whether a checkpoint still resumes (hack/fingerprint-diff names them).
#
# So a pull request that changes the config, or bumps the Debian toolchain the kernel
# is compiled with, says on its own summary that it strands every checkpoint in
# existence. That is not a reason to reject it — it is a release this repository makes
# deliberately, and the step exits 0 either way. It is a reason to know: the change
# that does this need not look like much, and a comment edited in this directory's
# Dockerfile is enough.
#
# It speaks only for the kernel: this workflow builds no QEMU, and the verdict says so
# rather than implying it checked the whole machine.
- name: What this kernel is, and what it breaks
env:
GH_TOKEN: ${{ github.token }}
run: |
set -euo pipefail
kernel=$(sha256sum _output/kernel/vmlinux | cut -d' ' -f1)
echo "kernel sha256: ${kernel}"
echo "config sha256: $(sha256sum _output/kernel/kernel-config | cut -d' ' -f1)"
hack/fingerprint-diff "kernel_sha256=${kernel}" | tee -a "$GITHUB_STEP_SUMMARY"
- name: Upload the kernel
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: vmlinux-${{ github.sha }}
path: |
_output/kernel/vmlinux
_output/kernel/kernel-config
retention-days: 30
if-no-files-found: error