ci: make build-kernel.yml reusable (workflow_call) and add devel_prs multi-PR builds - #25
Merged
Merged
Conversation
Bjordis Collaku (bjordiscollaku)
force-pushed
the
feat/pr-build-pipeline
branch
8 times, most recently
from
July 7, 2026 16:55
0500d0f to
3428e71
Compare
Bjordis Collaku (bjordiscollaku)
force-pushed
the
feat/pr-build-pipeline
branch
from
July 7, 2026 17:15
3428e71 to
3a69808
Compare
Bjordis Collaku (bjordiscollaku)
force-pushed
the
feat/pr-build-pipeline
branch
from
July 7, 2026 17:32
3a69808 to
9896116
Compare
Bjordis Collaku (bjordiscollaku)
added a commit
that referenced
this pull request
Jul 7, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR into resolute-qcom-devel (the merge ref, build-only) via the reusable build-kernel.yml on main. It lives on this branch because GitHub resolves pull_request workflows from the PR base branch, not the default branch. Depends on the workflow_call interface in #25; do not merge until #25 lands on main. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Bjordis Collaku (bjordiscollaku)
force-pushed
the
feat/pr-build-pipeline
branch
3 times, most recently
from
July 7, 2026 18:04
6ab0cfc to
44ad682
Compare
Simon Beaudoin (simonbeaudoin0935)
approved these changes
Jul 7, 2026
… check build-kernel.yml: - Add workflow_call trigger so premerge-pr.yml can call it as a reusable workflow without duplicating build logic. - Add devel_prs input (space-separated PR numbers against resolute-qcom-devel). Each PR is fetched and merged with --no-ff --no-commit before the build. Conflict or invalid input aborts immediately with a clear error. Modeled on qcom-next-pr in pkg-linux-qcom/build-kernel-deb.yml. - Add ref input to workflow_call so callers can pin an exact SHA (used by premerge-pr.yml to build the PR head, not the branch tip). - Remove dead if: inputs.runner == 'lecore-production' guard on S3 upload (runner is now always lecore-production). premerge-pr.yml: - New workflow triggered on pull_request_target targeting resolute-qcom-devel (opened, synchronize, reopened). - Uses pull_request_target (not pull_request) because resolute-qcom-devel is a kernel source tree with no .github/; pull_request_target resolves the workflow from the default branch. - Calls build-kernel.yml with suite=resolute-qcom-devel and ref=PR head SHA so each PR builds its exact commit in isolation. - Concurrency group per PR number cancels stale runs on new pushes. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
arch, flavor, and runner are constants for this repo and never vary: arch = arm64 (arm64-only kernel) flavor = qcom (only the qcom flavour is built) runner = lecore-production (only runner with S3 access) Remove them from workflow_dispatch inputs and hardcode directly in the job. The fromJSON runner map is replaced with the lecore label directly on runs-on. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Premerge builds should never upload to S3. The runner input removal made the S3 upload unconditional since the job always runs on lecore-production. Add a workflow_call-only skip_s3 boolean input to gate the upload step, and set it in premerge-pr.yml. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
The runner comment referenced ubuntu-24.04-arm and self-hosted options that were dropped when the runner input was removed. Also align the workflow_dispatch SUITE env default with the actual default input value (resolute-qcom-devel). Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
…atch build-kernel.yml no longer accepts arch, flavor, or runner as workflow_dispatch inputs (removed in a060b47). Passing them via gh workflow run causes GitHub to return HTTP 422 Unexpected inputs, silently breaking the trigger-build job on every Canonical sync run. Drop the three stale --field lines. suite and kernel_version are the only inputs needed; arch, flavor, and runner are now hardcoded inside build-kernel.yml. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
- remove arch, flavor, runner from build-kernel.yml inputs table (removed as inputs in a060b47, now hardcoded) - add devel_prs, ref, skip_s3 inputs to the table with workflow_dispatch vs workflow_call scope noted - fix trigger-build job description to drop the stale arch/flavor/runner fields (matches the fetch-source-pkg.yml fix in 1744ced) - update build steps list: note ref override on checkout, add devel_prs merge step, renumber, note skip_s3 on S3 upload step - add premerge-pr.yml section to workflows reference Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Address review of the pre-merge build feature: premerge-pr.yml (moved to .github/devel-workflows/ as a source, installed on resolute-qcom-devel): - Was pull_request_target reading the workflow from main and building the raw PR head SHA on the S3-credentialed self-hosted runner - a pwn-request, and it would never have fired: pull_request(_target) resolves the workflow from the PR base branch (resolute-qcom-devel), not the default branch. - Now pull_request (read-only token, no secrets) building the PR merge ref via build-kernel.yml@main, gated to same-repo (non-fork) PRs. Installed on the integration branch so the trigger actually fires. Static job name yields the stable 'Build check / Build' required-check name. build-kernel.yml: - devel_prs now validates each PR is open and targets the suite branch, and deepens the shallow checkout until a merge base exists before merging (the old code failed on any PR not based on the exact branch tip and misreported it as a conflict). - Fix shell-injection of inputs.devel_prs in the summary step (route via env). - Align the empty-suite checkout fallback with the resolute-qcom-devel default. docs/PIPELINE.md: correct the pull_request_target rationale, document the install-on-devel step and the residual credentialed-runner security note. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Bjordis Collaku (bjordiscollaku)
force-pushed
the
feat/pr-build-pipeline
branch
from
July 10, 2026 16:11
44ad682 to
7eeba02
Compare
Keerthi Gowda (keerthi-go)
approved these changes
Jul 10, 2026
Bjordis Collaku (bjordiscollaku)
added a commit
that referenced
this pull request
Jul 28, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR into resolute-qcom-devel (the merge ref, build-only) via the reusable build-kernel.yml on main. It lives on this branch because GitHub resolves pull_request workflows from the PR base branch, not the default branch. Depends on the workflow_call interface in #25; do not merge until #25 lands on main. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
ximiali
pushed a commit
to ximiali/pkg-linux-qcom-canonical-new
that referenced
this pull request
Jul 30, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR into resolute-qcom-devel (the merge ref, build-only) via the reusable build-kernel.yml on main. It lives on this branch because GitHub resolves pull_request workflows from the PR base branch, not the default branch. Depends on the workflow_call interface in qualcomm-linux#25; do not merge until qualcomm-linux#25 lands on main. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com> (cherry picked from commit 998080b)
github-actions Bot
pushed a commit
that referenced
this pull request
Aug 17, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR into resolute-qcom-devel (the merge ref, build-only) via the reusable build-kernel.yml on main. It lives on this branch because GitHub resolves pull_request workflows from the PR base branch, not the default branch. Depends on the workflow_call interface in #25; do not merge until #25 lands on main. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com> (cherry picked from commit 998080b)
github-actions Bot
pushed a commit
that referenced
this pull request
Sep 16, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR into resolute-qcom-devel (the merge ref, build-only) via the reusable build-kernel.yml on main. It lives on this branch because GitHub resolves pull_request workflows from the PR base branch, not the default branch. Depends on the workflow_call interface in #25; do not merge until #25 lands on main. Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com> (cherry picked from commit 998080b)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Turns
build-kernel.ymlinto a reusable workflow and adds a way to build one ormore open PRs on top of the integration branch. Two additions, plus an input cleanup:
workflow_callso the build can be invoked by other workflows, not only by amanual dispatch. This is the interface the pre-merge PR check consumes (that check
lives on
resolute-qcom-develin ci: pre-merge PR build check on resolute-qcom-devel #28, not in this PR).devel_prson manual dispatch: a space-separated list of open PRs againstresolute-qcom-devel, merged on top of the branch HEAD before building, forengineering and integration builds (e.g.
devel_prs: "42 43").Note
This PR does not contain the pre-merge check. It only adds the reusable interface
and inputs that #28 calls. Merge order: this PR first (so
build-kernel.yml@maingains
workflow_call), then #28.What changed
.github/workflows/build-kernel.ymlworkflow_callinterface (suite,kernel_version,devel_prs,ref,skip_s3) alongsideworkflow_dispatch. Adds thedevel_prsmanual input. Removes thearch/flavor/runnerinputs and hardcodes them (arm64/qcom/lecore-production, the only combination this repo builds). S3 upload is now gated byskip_s3(null-safe, so dispatched builds still upload).suitedefaults toresolute-qcom-devel..github/workflows/fetch-source-pkg.ymlarch/flavor/runnerfields so the auto-build trigger still validates.docs/PIPELINE.mddevel_prs, the reusable interface, and where the pre-merge check lives.How
devel_prsworksEach PR in the list is validated (it must exist, be open, and target the suite
branch), then merged in order on top of the branch HEAD. The checkout is shallow on
a ~1.43M-commit tree, so history is deepened only until a merge base is found
(bounded, never a full unshallow). A conflict aborts the build and names the PR.
The merges exist only in the build workspace; nothing is pushed.
The reusable interface
Two inputs exist only on
workflow_call, for programmatic callers:ref- an explicit git ref to build (for example a PR merge ref), overriding thesuite/kernel_versionresolution.skip_s3- build-only mode that skips the S3 upload.The pre-merge check in #28 uses both to build a PR's merge ref without publishing.
Manual dispatch and the sync's auto-build use the
workflow_dispatchinputs andupload to S3 exactly as before.
Validation
actionlint(with shellcheck) passes on all workflows.skip_s3is null-safe onworkflow_dispatch: a dispatched or sync-triggered buildstill uploads (the flag only exists on the call interface).
devel_prs(validation + the deepen-to-merge-base logic) was exercised by manualdispatch; a re-run after the review fixes is still worth doing before relying on it.