From 0107c2cad4000b163e5a35f4cb9f35b8f705be7e Mon Sep 17 00:00:00 2001 From: ScottW514 Date: Wed, 9 Sep 2026 13:28:05 -0400 Subject: [PATCH] Remove the cold-build workflow: Yocto builds on the build host only The yocto-cold-build workflow and its kas/ci.yml overlay built the release image on a hosted runner as a reproducibility probe. It never ran to completion, its first dispatch (2026-09-09) stopped on the runner's user-namespace rule, and a probe nobody runs is a trap. Every Yocto build, the release included, runs on the build host; the release proof is the local pipeline (release.sh) and the bench campaign. The pre-publish checklist loses its self-containment line to match. --- .github/workflows/yocto-cold-build.yml | 78 -------------------------- kas/ci.yml | 16 ------ scripts/release.sh | 1 - 3 files changed, 95 deletions(-) delete mode 100644 .github/workflows/yocto-cold-build.yml delete mode 100644 kas/ci.yml diff --git a/.github/workflows/yocto-cold-build.yml b/.github/workflows/yocto-cold-build.yml deleted file mode 100644 index 60d1e29..0000000 --- a/.github/workflows/yocto-cold-build.yml +++ /dev/null @@ -1,78 +0,0 @@ -# Cold-build reproducibility probe: proves a fresh clone still builds the -# release image, and publishes the artifact checksums for comparison -# against locally built releases. Dispatch-only - releases are built and -# signed on the maintainer's build host (see -# https://docs.forgefirm.org/technical/forgefirm/install-and-update/); this -# workflow never produces release artifacts. -# -# A cold Yocto build on a 4-core hosted runner takes hours and lives -# close to the 6-hour job cap; a timeout here is a data point, not an -# emergency. - -name: yocto-cold-build - -on: - workflow_dispatch: - -jobs: - build: - runs-on: ubuntu-latest - timeout-minutes: 360 - steps: - - name: Reclaim runner disk - run: | - sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc \ - /opt/hostedtoolcache/CodeQL /usr/local/.ghcup \ - /usr/local/share/boost - df -h / - - - name: Checkout forgefirm - uses: actions/checkout@v4 - with: - path: forgefirm - - # The kas config references meta-openglow as a local sibling - # (the release flow on the documentation site flips it to the - # pinned-remote block at release time). Every source repo the recipes - # build is fetched by pinned SRCREV; no other sibling is needed. - - name: Checkout meta-openglow (sibling) - uses: actions/checkout@v4 - with: - repository: openglow-org/meta-openglow - ref: scarthgap - path: meta-openglow - - - name: Host dependencies - run: | - sudo apt-get update -qq - sudo apt-get install -y -qq gawk wget git diffstat unzip texinfo \ - gcc build-essential chrpath socat cpio python3 python3-pip \ - python3-pexpect xz-utils debianutils iputils-ping python3-git \ - python3-jinja2 zstd liblz4-tool file locales libacl1 - sudo locale-gen en_US.UTF-8 - pip3 install kas - - # BitBake isolates the network of its tasks with a user namespace; - # the ubuntu-24.04 runner's AppArmor profile refuses that to an - # unprivileged process, so the build would stop before its first task. - - name: Allow unprivileged user namespaces (BitBake network isolation) - run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 - - - name: Build (rm_work, release image only) - working-directory: forgefirm - run: kas build kas/forgefirm-glowforge.yml:kas/ci.yml - - - name: Checksums - working-directory: forgefirm - run: | - cd build/tmp/deploy/images/glowforge - sha256sum $(readlink forgefirm-image-glowforge.rootfs.ext4) \ - $(readlink forgefirm-image-glowforge.rootfs.wic.gz) \ - | tee cold-build-checksums.txt "$GITHUB_STEP_SUMMARY" - - - name: Upload checksums - uses: actions/upload-artifact@v4 - with: - name: cold-build-checksums - path: forgefirm/build/tmp/deploy/images/glowforge/cold-build-checksums.txt - retention-days: 90 diff --git a/kas/ci.yml b/kas/ci.yml deleted file mode 100644 index b0515ee..0000000 --- a/kas/ci.yml +++ /dev/null @@ -1,16 +0,0 @@ -# CI overlay for the cold-build reproducibility workflow: merge after the -# main config (kas build kas/forgefirm-glowforge.yml:kas/ci.yml). -# rm_work keeps the build inside a hosted runner's disk budget; the -# release image alone is built (the dev image adds nothing to the -# reproducibility question). - -header: - version: 14 - -target: forgefirm-image - -local_conf_header: - ci: | - INHERIT += "rm_work" - BB_NUMBER_THREADS = "4" - PARALLEL_MAKE = "-j 4" diff --git a/scripts/release.sh b/scripts/release.sh index 7b3e62b..8dcd9ab 100644 --- a/scripts/release.sh +++ b/scripts/release.sh @@ -369,7 +369,6 @@ cat <