Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
47 commits
Select commit Hold shift + click to select a range
6202824
bsp: fix existing Jaguar U-Boot patches
ajlennon Sep 12, 2026
7c184c7
ci: enforce layer adoption regression gate
ajlennon Sep 11, 2026
82f2c51
ci: fix layer gate expressions
ajlennon Sep 11, 2026
6b8e574
ci: bound layer gate build concurrency
ajlennon Sep 11, 2026
71c01cd
ci: use current Actions runtimes
ajlennon Sep 11, 2026
c73dd4b
ci: emit layer matrix without jq
ajlennon Sep 11, 2026
58bb309
ci: route Yocto jobs to capable runner
ajlennon Sep 11, 2026
ce0b9da
ci: strengthen layer adoption evidence
ajlennon Sep 11, 2026
372d90c
ci: preserve protected layer adoption tuples
ajlennon Sep 11, 2026
9d6bb5a
ci: test protected layer adoption matrix
ajlennon Sep 11, 2026
06f1536
ci: protect exact product feature tuples
ajlennon Sep 12, 2026
b9207b9
ci: exercise signing in layer adoption gate
ajlennon Sep 12, 2026
303978b
ci: use valid job-level key path
ajlennon Sep 12, 2026
4b2cfa7
ci: bound layer gate disk usage
ajlennon Sep 12, 2026
5cf9737
ci: consolidate layer adoption regression on ai-tools
ajlennon Sep 12, 2026
28be102
ci: run container steps with bash
ajlennon Sep 12, 2026
0ba5fa3
ci: keep kas overlay inside worktree
ajlennon Sep 12, 2026
dc1079d
ci: quote layer state normalisation safely
ajlennon Sep 12, 2026
d58b88a
ci: replay captured command failures
ajlennon Sep 12, 2026
4998160
ci: initialize protected layer submodules
ajlennon Sep 12, 2026
4e07c3b
ci: initialize protected layer worktrees
ajlennon Sep 12, 2026
aba0a4d
ci: share kas worktree preparation
ajlennon Sep 12, 2026
c423642
ci: track current bitbake dependency graph
ajlennon Sep 12, 2026
67e9f6d
ci: diagnose selected environment mismatches
ajlennon Sep 12, 2026
62e7455
ci: use inode-aware disk thresholds
ajlennon Sep 12, 2026
f7bdd20
ci: bind local kas changes to adoption gate
ajlennon Sep 12, 2026
b5380f5
ci: validate kernel signing identity
ajlennon Sep 12, 2026
b08700e
ci: force test signing paths
ajlennon Sep 12, 2026
fc72fbd
ci: canonicalise layer adoption evidence
ajlennon Sep 12, 2026
fbc6f4d
ci: keep adoption gate on controlled runner
ajlennon Sep 12, 2026
531a6c2
ci: key baseline cache by capture schema
ajlennon Sep 12, 2026
9093e7a
ci: source warnings from cooker logs
ajlennon Sep 12, 2026
88a53cd
ci: normalise encoded checkout provenance
ajlennon Sep 12, 2026
f7c6d6e
ci: audit immutable baseline repair
ajlennon Sep 13, 2026
014a301
ci: include packaging baseline repair
ajlennon Sep 13, 2026
d767d4c
ci: include Handheld DTS baseline repair
ajlennon Sep 13, 2026
25e4e8a
ci: include Handheld DTS baseline repair
ajlennon Sep 13, 2026
9e66b1b
ci: retain repaired empty package baseline
ajlennon Sep 13, 2026
cc48e39
ci: include remaining DTS baseline repairs
ajlennon Sep 13, 2026
459641f
ci: make kernel warnings sstate-independent
ajlennon Sep 13, 2026
28311cb
ci: include Phasora SPDX baseline repair
ajlennon Sep 13, 2026
843ab3b
ci: match renamed license repair surface
ajlennon Sep 13, 2026
6c4a0aa
ci: treat removed warnings as improvements
ajlennon Sep 13, 2026
b47dc37
ci: shard layer adoption tuples
ajlennon Sep 13, 2026
e47e9da
ci: materialize LFS-backed KAS configs
ajlennon Sep 13, 2026
e8c94ce
ci: retire Jaguar inst and Phasora tuples
ajlennon Sep 13, 2026
079fe76
ci: focus adoption gate on Jaguar screen
ajlennon Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,6 @@
*.bin filter=lfs diff=lfs merge=lfs -text
*.itb filter=lfs diff=lfs merge=lfs -text
*mfgtool* filter=lfs diff=lfs merge=lfs -text
# Build entry points are source, even when their names contain "mfgtool".
scripts/kas-build-mfgtools.sh -filter -diff -merge text eol=lf
fitImage-* filter=lfs diff=lfs merge=lfs -text
3 changes: 3 additions & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
self-hosted-runner:
labels:
- yocto
203 changes: 0 additions & 203 deletions .github/workflows/kas-build-ci.yml

This file was deleted.

170 changes: 170 additions & 0 deletions .github/workflows/layer-adoption-gate.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,170 @@
name: Layer Adoption Gate

on:
pull_request:
branches: [main, develop]
push:
branches: [main, develop]
workflow_dispatch:
inputs:
base_sha:
description: Baseline commit to compare
required: true

concurrency:
group: layer-adoption-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true

defaults:
run:
shell: bash

jobs:
detect:
name: Detect material layer change
runs-on: [self-hosted, Linux, X64, yocto, ai-tools]
outputs:
material: ${{ steps.detect.outputs.material }}
base_sha: ${{ steps.base.outputs.sha }}
tuple_ids: ${{ steps.detect.outputs.tuple_ids }}
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
- id: base
name: Resolve immutable baseline
env:
PR_BASE: ${{ github.event.pull_request.base.sha }}
PUSH_BASE: ${{ github.event.before }}
INPUT_BASE: ${{ inputs.base_sha }}
run: |
sha="${PR_BASE:-${INPUT_BASE:-${PUSH_BASE:-}}}"
if [ -z "$sha" ] || printf '%s' "$sha" | grep -Eq '^0+$'; then
sha=$(git rev-parse HEAD^)
fi
git cat-file -e "$sha^{commit}"
echo "sha=$sha" >> "$GITHUB_OUTPUT"
- id: detect
name: Validate repository and require an adoption contract
run: |
python3 -m unittest discover -s scripts/validation/tests -p 'test_*.py'
find scripts -type f -name '*.sh' -print0 | xargs -0 -r -n1 bash -n
python3 -m json.tool ci/layer-adoption-contract.json >/dev/null
python3 -m json.tool ci/layer-adoption-tuples.json >/dev/null
# Mail-format patch payloads legitimately contain the conventional
# "-- " separator. Check repository sources without rewriting the
# third-party patches that BitBake applies.
git diff --check '${{ steps.base.outputs.sha }}...${{ github.sha }}' -- . ':(exclude)**/*.patch'
python3 scripts/validation/detect-layer-adoption.py \
--base '${{ steps.base.outputs.sha }}' \
--head '${{ github.sha }}' \
--github-output "$GITHUB_OUTPUT"
tuple_ids=$(python3 -c 'import json; print(json.dumps([entry["id"] for entry in json.load(open("ci/layer-adoption-tuples.json"))["tuples"]], separators=(",", ":")))')
echo "tuple_ids=$tuple_ids" >> "$GITHUB_OUTPUT"
regression:
name: Existing product regression (${{ matrix.tuple_id }})
needs: detect
if: needs.detect.outputs.material == 'true'
strategy:
fail-fast: false
matrix:
tuple_id: ${{ fromJSON(needs.detect.outputs.tuple_ids) }}
# Each tuple is an independent shard so one failure cannot hide later
# product failures. The final Layer Adoption Gate remains the single
# branch-protection contract, and local driver runs still cover all tuples.
runs-on: [self-hosted, Linux, X64, yocto, ai-tools]
container:
image: ghcr.io/siemens/kas/kas@sha256:d989add57fc441fe9e27bb2dd6ed98c5597b44c807928e35a72dc1cfbdda9abe
# Match the dedicated ai-tools runner account so BitBake's root-user
# sanity check remains active and bind-mounted cache files stay writable.
options: --privileged --platform linux/amd64 --user 1002:1002 -v /home/ghrunner/yocto-layer-adoption:/var/cache/layer-adoption
env:
LAYER_ADOPTION_CACHE: /var/cache/layer-adoption
steps:
- name: Reset job-owned workspace
run: |
workspace=$(realpath -m -- "$GITHUB_WORKSPACE")
test -n "$workspace"
test "$workspace" != /
for name in candidate baseline evidence; do
target=$(realpath -m -- "$workspace/$name")
test "$(dirname "$target")" = "$workspace"
rm -rf -- "$target"
done
- uses: actions/checkout@v7
with:
fetch-depth: 0
path: candidate
- name: Create baseline worktree
working-directory: candidate
run: git worktree add ../baseline '${{ needs.detect.outputs.base_sha }}'
- name: Require safe build capacity
run: |
available_kib=$(df -Pk "$GITHUB_WORKSPACE" | awk 'NR == 2 {print $4}')
minimum_kib=$((150 * 1024 * 1024))
if [ "$available_kib" -lt "$minimum_kib" ]; then
echo "ERROR: layer-adoption build requires at least 150 GiB free; found $((available_kib / 1024 / 1024)) GiB" >&2
exit 1
fi
- name: Prepare persistent test-only signing identity
run: |
set -euo pipefail
keys="$LAYER_ADOPTION_CACHE/test-keys"
if ! candidate/scripts/validation/generate-layer-adoption-test-keys.sh \
--check "$keys"; then
test "$keys" = /var/cache/layer-adoption/test-keys
rm -rf -- "$keys"
rm -rf -- "$LAYER_ADOPTION_CACHE/baselines"
temporary=$(mktemp -d "$LAYER_ADOPTION_CACHE/.test-keys.XXXXXX")
candidate/scripts/validation/generate-layer-adoption-test-keys.sh "$temporary"
mv "$temporary" "$keys"
fi
- name: Build and compare every protected tuple
run: |
python3 candidate/scripts/validation/run-layer-adoption-regression.py \
--baseline baseline \
--candidate candidate \
--evidence evidence \
--cache "$LAYER_ADOPTION_CACHE" \
--test-keys "$LAYER_ADOPTION_CACHE/test-keys" \
--tuple-id '${{ matrix.tuple_id }}'
- name: Preserve comparison evidence
if: always()
uses: actions/upload-artifact@v7
with:
name: layer-adoption-evidence-${{ matrix.tuple_id }}
path: evidence
retention-days: 14
- name: Remove job-owned build trees
if: always()
run: |
workspace=$(realpath -m -- "$GITHUB_WORKSPACE")
test -n "$workspace"
test "$workspace" != /
for name in candidate/build baseline/build evidence; do
target=$(realpath -m -- "$workspace/$name")
case "$target" in
"$workspace/candidate/build"|"$workspace/baseline/build"|"$workspace/evidence") ;;
*) echo "ERROR: refusing unsafe cleanup target: $target" >&2; exit 1 ;;
esac
rm -rf -- "$target"
done

required:
name: Layer Adoption Gate
needs: [detect, regression]
if: always()
runs-on: [self-hosted, Linux, X64, yocto, ai-tools]
steps:
- name: Enforce gate result
env:
DETECT: ${{ needs.detect.result }}
MATERIAL: ${{ needs.detect.outputs.material }}
REGRESSION: ${{ needs.regression.result }}
run: |
test "$DETECT" = success
if [ "$MATERIAL" = true ]; then
test "$REGRESSION" = success
else
test "$REGRESSION" = skipped
fi
Loading