From 1e921e0a624045a34ef28a605c5cda8b39c4c2e2 Mon Sep 17 00:00:00 2001 From: Benjamin Leggett Date: Tue, 26 Aug 2025 13:37:28 -0400 Subject: [PATCH 1/4] Host kernel build is running out of build space :/ --- .github/workflows/build.yml | 3 +++ .github/workflows/test.yml | 3 +++ 2 files changed, 6 insertions(+) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 4cca947f..e8be5ed4 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -31,6 +31,9 @@ jobs: with: egress-policy: audit + - name: Maximize build space + uses: ublue-os/remove-unwanted-software@6bdddc50e67c21ebe9d3316539b3a025345fdc81 # v9 + - name: checkout repository uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index b3c6834e..a58c71fa 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -23,6 +23,9 @@ jobs: with: egress-policy: audit + - name: Maximize build space + uses: ublue-os/remove-unwanted-software@6bdddc50e67c21ebe9d3316539b3a025345fdc81 # v9 + - name: checkout repository uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: From 3f4f4e15f4214b053bc268d350ac919eadca298c Mon Sep 17 00:00:00 2001 From: Benjamin Leggett Date: Tue, 26 Aug 2025 14:08:18 -0400 Subject: [PATCH 2/4] use large runner for test too, that should be better --- .github/workflows/build.yml | 3 --- .github/workflows/test.yml | 3 --- 2 files changed, 6 deletions(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index e8be5ed4..4cca947f 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -31,9 +31,6 @@ jobs: with: egress-policy: audit - - name: Maximize build space - uses: ublue-os/remove-unwanted-software@6bdddc50e67c21ebe9d3316539b3a025345fdc81 # v9 - - name: checkout repository uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index a58c71fa..b3c6834e 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -23,9 +23,6 @@ jobs: with: egress-policy: audit - - name: Maximize build space - uses: ublue-os/remove-unwanted-software@6bdddc50e67c21ebe9d3316539b3a025345fdc81 # v9 - - name: checkout repository uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 with: From a3c189066ae6acc668bcca0b7261969599c318a0 Mon Sep 17 00:00:00 2001 From: Benjamin Leggett Date: Tue, 26 Aug 2025 16:53:49 -0400 Subject: [PATCH 3/4] Use workflow-call to share templates and runner config --- .github/workflows/build.yml | 88 +++------------------------------ .github/workflows/matrix.yml | 94 ++++++++++++++++++++++++++++++++++++ .github/workflows/test.yml | 68 ++------------------------ config.yaml | 3 +- 4 files changed, 107 insertions(+), 146 deletions(-) create mode 100644 .github/workflows/matrix.yml diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 4cca947f..6df5618d 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -1,4 +1,4 @@ -name: Build Kernels +name: Kernel Build on: # Weekly auto-build schedule: @@ -15,87 +15,15 @@ on: type: boolean default: true required: true + +# this job will publish images, and needs higher perms. permissions: contents: read packages: write id-token: write -concurrency: - group: "kernel-builder" jobs: - matrix: - name: matrix - runs-on: ubuntu-latest - steps: - - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@002fdce3c6a235733a90a27c80493a3241e56863 # v2.12.1 - with: - egress-policy: audit - - - name: checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - with: - submodules: recursive - - name: install dependencies - run: ./hack/build/install-matrix-deps.sh - - name: generate matrix - run: 'PATH="${HOME}/go/bin:${PATH}" ./hack/build/generate-matrix.sh "${{ inputs.spec }}"' - - name: upload matrix - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 - with: - name: matrix - path: "matrix.json" - compression-level: 0 - - name: capture matrix - id: capture-matrix - run: > - echo "matrix=$(cat matrix.json)" >> "${GITHUB_OUTPUT}" - outputs: - matrix: "${{ steps.capture-matrix.outputs.matrix }}" - build: - name: "build ${{ matrix.builds.version }} ${{ matrix.builds.flavor }}" - needs: matrix - strategy: - fail-fast: false - matrix: ${{ fromJSON(needs.matrix.outputs.matrix) }} - runs-on: "${{ matrix.builds.runner }}" - env: - KERNEL_PUBLISH: "${{ inputs.publish }}" - KERNEL_VERSION: "${{ matrix.builds.version }}" - KERNEL_SRC_URL: "${{ matrix.builds.source }}" - FIRMWARE_URL: "${{ matrix.builds.firmware_url }}" - FIRMWARE_SIG_URL: "${{ matrix.builds.firmware_sig_url }}" - KERNEL_FLAVOR: "${{ matrix.builds.flavor }}" - KERNEL_TAGS: "${{ join(matrix.builds.tags, ',') }}" - KERNEL_ARCHITECTURES: "${{ join(matrix.builds.architectures, ',') }}" - steps: - - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@002fdce3c6a235733a90a27c80493a3241e56863 # v2.12.1 - with: - egress-policy: audit - - - name: checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - with: - submodules: recursive - - name: install cosign - uses: sigstore/cosign-installer@3454372f43399081ed03b604cb2d021dabca52bb # v3.8.2 - - name: docker setup linux-kernel-oci - run: sudo python3 ./hack/build/docker-setup.py - - name: docker setup buildx - uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3 - - name: docker login ghcr.io - uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3 - with: - registry: ghcr.io - username: "${{github.actor}}" - password: "${{secrets.GITHUB_TOKEN}}" - - name: generate docker script - run: "./hack/build/generate-docker-script.sh" - - name: upload docker script - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 - with: - name: "build-${{ matrix.builds.version }}-${{ matrix.builds.flavor }}.sh" - path: "docker.sh" - compression-level: 0 - - name: run docker script - run: sh -x docker.sh + test: + uses: ./.github/workflows/matrix.yml + with: + spec: inputs.spec + publish: inputs.publish diff --git a/.github/workflows/matrix.yml b/.github/workflows/matrix.yml new file mode 100644 index 00000000..cb5e9021 --- /dev/null +++ b/.github/workflows/matrix.yml @@ -0,0 +1,94 @@ +name: Build Kernel Matrix +on: + workflow_call: + inputs: + spec: + description: 'Build Specification' + type: string + default: "new" + required: true + publish: + description: 'Publish Builds' + type: boolean + default: true + required: true +concurrency: + group: "kernel-builder" +jobs: + matrix: + name: matrix + runs-on: ubuntu-latest + steps: + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@002fdce3c6a235733a90a27c80493a3241e56863 # v2.12.1 + with: + egress-policy: audit + + - name: checkout repository + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + with: + submodules: recursive + - name: install dependencies + run: ./hack/build/install-matrix-deps.sh + - name: generate matrix + run: 'PATH="${HOME}/go/bin:${PATH}" ./hack/build/generate-matrix.sh "${{ inputs.spec }}"' + - name: upload matrix + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + with: + name: matrix + path: "matrix.json" + compression-level: 0 + - name: capture matrix + id: capture-matrix + run: > + echo "matrix=$(cat matrix.json)" >> "${GITHUB_OUTPUT}" + outputs: + matrix: "${{ steps.capture-matrix.outputs.matrix }}" + build: + name: "build ${{ matrix.builds.version }} ${{ matrix.builds.flavor }}" + needs: matrix + strategy: + fail-fast: false + matrix: ${{ fromJSON(needs.matrix.outputs.matrix) }} + runs-on: "${{ matrix.builds.runner }}" + env: + KERNEL_PUBLISH: "${{ inputs.publish }}" + KERNEL_VERSION: "${{ matrix.builds.version }}" + KERNEL_SRC_URL: "${{ matrix.builds.source }}" + FIRMWARE_URL: "${{ matrix.builds.firmware_url }}" + FIRMWARE_SIG_URL: "${{ matrix.builds.firmware_sig_url }}" + KERNEL_FLAVOR: "${{ matrix.builds.flavor }}" + KERNEL_TAGS: "${{ join(matrix.builds.tags, ',') }}" + KERNEL_ARCHITECTURES: "${{ join(matrix.builds.architectures, ',') }}" + steps: + - name: Harden the runner (Audit all outbound calls) + uses: step-security/harden-runner@002fdce3c6a235733a90a27c80493a3241e56863 # v2.12.1 + with: + egress-policy: audit + + - name: checkout repository + uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 + with: + submodules: recursive + - name: install cosign + uses: sigstore/cosign-installer@3454372f43399081ed03b604cb2d021dabca52bb # v3.8.2 + - name: docker setup linux-kernel-oci + run: sudo python3 ./hack/build/docker-setup.py + - name: docker setup buildx + uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3 + - name: docker login ghcr.io + uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3 + with: + registry: ghcr.io + username: "${{github.actor}}" + password: "${{secrets.GITHUB_TOKEN}}" + - name: generate docker script + run: "./hack/build/generate-docker-script.sh" + - name: upload docker script + uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 + with: + name: "build-${{ matrix.builds.version }}-${{ matrix.builds.flavor }}.sh" + path: "docker.sh" + compression-level: 0 + - name: run docker script + run: sh -x docker.sh diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index b3c6834e..ad622489 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -7,69 +7,9 @@ on: permissions: contents: read packages: read -env: - TEST_MATRIX_SPEC: "only-latest:flavor=host,zone,zone-nvidiagpu" jobs: test: - name: test - runs-on: edera-large - env: - FIRMWARE_URL: "https://cdn.kernel.org/pub/linux/kernel/firmware/linux-firmware-20250410.tar.xz" - FIRMWARE_SIG_URL: "https://cdn.kernel.org/pub/linux/kernel/firmware/linux-firmware-20250410.tar.sign" - KERNEL_ARCHITECTURES: "x86_64" - steps: - - name: Harden the runner (Audit all outbound calls) - uses: step-security/harden-runner@002fdce3c6a235733a90a27c80493a3241e56863 # v2.12.1 - with: - egress-policy: audit - - - name: checkout repository - uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 - with: - submodules: recursive - - name: install dependencies - run: ./hack/build/install-matrix-deps.sh - - name: generate spec-new matrix - run: 'PATH="${HOME}/go/bin:${PATH}" KERNEL_BUILD_SPEC="new" ./hack/build/generate-matrix.sh' - - name: upload spec-new matrix - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 - with: - name: spec-new-matrix - path: "matrix.json" - compression-level: 0 - - name: generate spec-rebuild matrix - run: 'PATH="${HOME}/go/bin:${PATH}" KERNEL_BUILD_SPEC="rebuild" ./hack/build/generate-matrix.sh' - - name: upload spec-rebuild matrix - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 - with: - name: spec-rebuild-matrix - path: "matrix.json" - compression-level: 0 - - name: generate test matrix - run: 'PATH="${HOME}/go/bin:${PATH}" ./hack/build/generate-matrix.sh "${TEST_MATRIX_SPEC}"' - - name: upload test matrix - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 - with: - name: test-matrix - path: "matrix.json" - compression-level: 0 - - name: docker setup linux-kernel-oci - run: sudo python3 ./hack/build/docker-setup.py - - name: docker setup buildx - uses: docker/setup-buildx-action@b5ca514318bd6ebac0fb2aedd5d36ec1b5c232a2 # v3 - - name: docker login ghcr.io - uses: docker/login-action@74a5d142397b4f367a81961eba4e8cd7edddf772 # v3 - with: - registry: ghcr.io - username: "${{github.actor}}" - password: "${{secrets.GITHUB_TOKEN}}" - - name: generate docker script - run: "./hack/build/generate-docker-script.sh matrix.json" - - name: upload docker script - uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # v4 - with: - name: "docker.sh" - path: "docker.sh" - compression-level: 0 - - name: run docker script - run: sh -x docker.sh + uses: ./.github/workflows/matrix.yml + with: + spec: "only-latest:flavor=host,zone,zone-nvidiagpu" + publish: false diff --git a/config.yaml b/config.yaml index a47b57ef..115f22e2 100644 --- a/config.yaml +++ b/config.yaml @@ -20,8 +20,7 @@ flavors: - 'nvidia-575.64.03' - 'nvidia-575.57.08' constraints: - series: - - '6.15' + lower: '6.15' - name: zone-openpax constraints: series: From 4723b4d2dce9e2113752542e7002a5052d63981f Mon Sep 17 00:00:00 2001 From: Benjamin Leggett Date: Wed, 27 Aug 2025 12:30:00 -0400 Subject: [PATCH 4/4] Drop oldest NV kernel (no longer builds with 6.16) --- config.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/config.yaml b/config.yaml index 115f22e2..0c08b29b 100644 --- a/config.yaml +++ b/config.yaml @@ -18,7 +18,6 @@ flavors: local_tags: - 'nvidia-575.64.05' - 'nvidia-575.64.03' - - 'nvidia-575.57.08' constraints: lower: '6.15' - name: zone-openpax