mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-28 09:11:11 -07:00
Remove the cold-build workflow: Yocto builds on the build host only
The yocto-cold-build workflow and its kas/ci.yml overlay built the release image on a hosted runner as a reproducibility probe. It never ran to completion, its first dispatch (2026-09-09) stopped on the runner's user-namespace rule, and a probe nobody runs is a trap. Every Yocto build, the release included, runs on the build host; the release proof is the local pipeline (release.sh) and the bench campaign. The pre-publish checklist loses its self-containment line to match.
This commit is contained in:
@@ -1,78 +0,0 @@
|
||||
# Cold-build reproducibility probe: proves a fresh clone still builds the
|
||||
# release image, and publishes the artifact checksums for comparison
|
||||
# against locally built releases. Dispatch-only - releases are built and
|
||||
# signed on the maintainer's build host (see
|
||||
# https://docs.forgefirm.org/technical/forgefirm/install-and-update/); this
|
||||
# workflow never produces release artifacts.
|
||||
#
|
||||
# A cold Yocto build on a 4-core hosted runner takes hours and lives
|
||||
# close to the 6-hour job cap; a timeout here is a data point, not an
|
||||
# emergency.
|
||||
|
||||
name: yocto-cold-build
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 360
|
||||
steps:
|
||||
- name: Reclaim runner disk
|
||||
run: |
|
||||
sudo rm -rf /usr/share/dotnet /usr/local/lib/android /opt/ghc \
|
||||
/opt/hostedtoolcache/CodeQL /usr/local/.ghcup \
|
||||
/usr/local/share/boost
|
||||
df -h /
|
||||
|
||||
- name: Checkout forgefirm
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
path: forgefirm
|
||||
|
||||
# The kas config references meta-openglow as a local sibling
|
||||
# (the release flow on the documentation site flips it to the
|
||||
# pinned-remote block at release time). Every source repo the recipes
|
||||
# build is fetched by pinned SRCREV; no other sibling is needed.
|
||||
- name: Checkout meta-openglow (sibling)
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: openglow-org/meta-openglow
|
||||
ref: scarthgap
|
||||
path: meta-openglow
|
||||
|
||||
- name: Host dependencies
|
||||
run: |
|
||||
sudo apt-get update -qq
|
||||
sudo apt-get install -y -qq gawk wget git diffstat unzip texinfo \
|
||||
gcc build-essential chrpath socat cpio python3 python3-pip \
|
||||
python3-pexpect xz-utils debianutils iputils-ping python3-git \
|
||||
python3-jinja2 zstd liblz4-tool file locales libacl1
|
||||
sudo locale-gen en_US.UTF-8
|
||||
pip3 install kas
|
||||
|
||||
# BitBake isolates the network of its tasks with a user namespace;
|
||||
# the ubuntu-24.04 runner's AppArmor profile refuses that to an
|
||||
# unprivileged process, so the build would stop before its first task.
|
||||
- name: Allow unprivileged user namespaces (BitBake network isolation)
|
||||
run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
|
||||
|
||||
- name: Build (rm_work, release image only)
|
||||
working-directory: forgefirm
|
||||
run: kas build kas/forgefirm-glowforge.yml:kas/ci.yml
|
||||
|
||||
- name: Checksums
|
||||
working-directory: forgefirm
|
||||
run: |
|
||||
cd build/tmp/deploy/images/glowforge
|
||||
sha256sum $(readlink forgefirm-image-glowforge.rootfs.ext4) \
|
||||
$(readlink forgefirm-image-glowforge.rootfs.wic.gz) \
|
||||
| tee cold-build-checksums.txt "$GITHUB_STEP_SUMMARY"
|
||||
|
||||
- name: Upload checksums
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: cold-build-checksums
|
||||
path: forgefirm/build/tmp/deploy/images/glowforge/cold-build-checksums.txt
|
||||
retention-days: 90
|
||||
Reference in New Issue
Block a user