Skip to content

ci: make build-kernel.yml reusable (workflow_call) and add devel_prs multi-PR builds - #25

Merged
Bjordis Collaku (bjordiscollaku) merged 7 commits into
mainfrom
feat/pr-build-pipeline
Jul 11, 2026
Merged

Bjordis Collaku (bjordiscollaku) merged 7 commits into
mainfrom
feat/pr-build-pipeline

Conversation

@bjordiscollaku

@bjordiscollaku Bjordis Collaku (bjordiscollaku) commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Turns build-kernel.yml into a reusable workflow and adds a way to build one or
more open PRs on top of the integration branch. Two additions, plus an input cleanup:

  • workflow_call so the build can be invoked by other workflows, not only by a
    manual dispatch. This is the interface the pre-merge PR check consumes (that check
    lives on resolute-qcom-devel in ci: pre-merge PR build check on resolute-qcom-devel #28, not in this PR).
  • devel_prs on manual dispatch: a space-separated list of open PRs against
    resolute-qcom-devel, merged on top of the branch HEAD before building, for
    engineering and integration builds (e.g. devel_prs: "42 43").

Note

This PR does not contain the pre-merge check. It only adds the reusable interface
and inputs that #28 calls. Merge order: this PR first (so build-kernel.yml@main
gains workflow_call), then #28.

What changed

File Change
.github/workflows/build-kernel.yml Adds a workflow_call interface (suite, kernel_version, devel_prs, ref, skip_s3) alongside workflow_dispatch. Adds the devel_prs manual input. Removes the arch/flavor/runner inputs and hardcodes them (arm64 / qcom / lecore-production, the only combination this repo builds). S3 upload is now gated by skip_s3 (null-safe, so dispatched builds still upload). suite defaults to resolute-qcom-devel.
.github/workflows/fetch-source-pkg.yml Sync dispatch drops the now-removed arch/flavor/runner fields so the auto-build trigger still validates.
docs/PIPELINE.md Documents devel_prs, the reusable interface, and where the pre-merge check lives.

How devel_prs works

Each PR in the list is validated (it must exist, be open, and target the suite
branch), then merged in order on top of the branch HEAD. The checkout is shallow on
a ~1.43M-commit tree, so history is deepened only until a merge base is found
(bounded, never a full unshallow). A conflict aborts the build and names the PR.
The merges exist only in the build workspace; nothing is pushed.

The reusable interface

Two inputs exist only on workflow_call, for programmatic callers:

  • ref - an explicit git ref to build (for example a PR merge ref), overriding the
    suite/kernel_version resolution.
  • skip_s3 - build-only mode that skips the S3 upload.

The pre-merge check in #28 uses both to build a PR's merge ref without publishing.
Manual dispatch and the sync's auto-build use the workflow_dispatch inputs and
upload to S3 exactly as before.

Validation

  • actionlint (with shellcheck) passes on all workflows.
  • skip_s3 is null-safe on workflow_dispatch: a dispatched or sync-triggered build
    still uploads (the flag only exists on the call interface).
  • devel_prs (validation + the deepen-to-merge-base logic) was exercised by manual
    dispatch; a re-run after the review fixes is still worth doing before relying on it.

@bjordiscollaku
Bjordis Collaku (bjordiscollaku) force-pushed the feat/pr-build-pipeline branch 8 times, most recently from 0500d0f to 3428e71 Compare July 7, 2026 16:55
@bjordiscollaku Bjordis Collaku (bjordiscollaku) changed the title ci: add devel_prs input, workflow_call, and premerge-pr build check ci: pre-merge build check and apply-PRs builds for resolute-qcom-devel Jul 7, 2026
Bjordis Collaku (bjordiscollaku) added a commit that referenced this pull request Jul 7, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR
into resolute-qcom-devel (the merge ref, build-only) via the reusable
build-kernel.yml on main. It lives on this branch because GitHub resolves
pull_request workflows from the PR base branch, not the default branch.

Depends on the workflow_call interface in #25;
do not merge until #25 lands on main.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
@bjordiscollaku
Bjordis Collaku (bjordiscollaku) force-pushed the feat/pr-build-pipeline branch 3 times, most recently from 6ab0cfc to 44ad682 Compare July 7, 2026 18:04
@bjordiscollaku Bjordis Collaku (bjordiscollaku) changed the title ci: pre-merge build check and apply-PRs builds for resolute-qcom-devel ci: make build-kernel.yml reusable (workflow_call) and add devel_prs multi-PR builds Jul 9, 2026
… check

build-kernel.yml:
- Add workflow_call trigger so premerge-pr.yml can call it as a
  reusable workflow without duplicating build logic.
- Add devel_prs input (space-separated PR numbers against
  resolute-qcom-devel). Each PR is fetched and merged with
  --no-ff --no-commit before the build. Conflict or invalid input
  aborts immediately with a clear error. Modeled on qcom-next-pr
  in pkg-linux-qcom/build-kernel-deb.yml.
- Add ref input to workflow_call so callers can pin an exact SHA
  (used by premerge-pr.yml to build the PR head, not the branch tip).
- Remove dead if: inputs.runner == 'lecore-production' guard on S3
  upload (runner is now always lecore-production).

premerge-pr.yml:
- New workflow triggered on pull_request_target targeting
  resolute-qcom-devel (opened, synchronize, reopened).
- Uses pull_request_target (not pull_request) because
  resolute-qcom-devel is a kernel source tree with no .github/;
  pull_request_target resolves the workflow from the default branch.
- Calls build-kernel.yml with suite=resolute-qcom-devel and
  ref=PR head SHA so each PR builds its exact commit in isolation.
- Concurrency group per PR number cancels stale runs on new pushes.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
arch, flavor, and runner are constants for this repo and never vary:
  arch   = arm64          (arm64-only kernel)
  flavor = qcom           (only the qcom flavour is built)
  runner = lecore-production  (only runner with S3 access)

Remove them from workflow_dispatch inputs and hardcode directly in
the job. The fromJSON runner map is replaced with the lecore label
directly on runs-on.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Premerge builds should never upload to S3. The runner input removal
made the S3 upload unconditional since the job always runs on
lecore-production. Add a workflow_call-only skip_s3 boolean input to
gate the upload step, and set it in premerge-pr.yml.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
The runner comment referenced ubuntu-24.04-arm and self-hosted options
that were dropped when the runner input was removed. Also align the
workflow_dispatch SUITE env default with the actual default input value
(resolute-qcom-devel).

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
…atch

build-kernel.yml no longer accepts arch, flavor, or runner as workflow_dispatch
inputs (removed in a060b47). Passing them via gh workflow run causes GitHub
to return HTTP 422 Unexpected inputs, silently breaking the trigger-build job
on every Canonical sync run.

Drop the three stale --field lines. suite and kernel_version are the only
inputs needed; arch, flavor, and runner are now hardcoded inside build-kernel.yml.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
- remove arch, flavor, runner from build-kernel.yml inputs table (removed
  as inputs in a060b47, now hardcoded)
- add devel_prs, ref, skip_s3 inputs to the table with workflow_dispatch
  vs workflow_call scope noted
- fix trigger-build job description to drop the stale arch/flavor/runner
  fields (matches the fetch-source-pkg.yml fix in 1744ced)
- update build steps list: note ref override on checkout, add devel_prs
  merge step, renumber, note skip_s3 on S3 upload step
- add premerge-pr.yml section to workflows reference

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
Address review of the pre-merge build feature:

premerge-pr.yml (moved to .github/devel-workflows/ as a source, installed on
resolute-qcom-devel):
- Was pull_request_target reading the workflow from main and building the raw PR
  head SHA on the S3-credentialed self-hosted runner - a pwn-request, and it
  would never have fired: pull_request(_target) resolves the workflow from the
  PR base branch (resolute-qcom-devel), not the default branch.
- Now pull_request (read-only token, no secrets) building the PR merge ref via
  build-kernel.yml@main, gated to same-repo (non-fork) PRs. Installed on the
  integration branch so the trigger actually fires. Static job name yields the
  stable 'Build check / Build' required-check name.

build-kernel.yml:
- devel_prs now validates each PR is open and targets the suite branch, and
  deepens the shallow checkout until a merge base exists before merging (the old
  code failed on any PR not based on the exact branch tip and misreported it as a
  conflict).
- Fix shell-injection of inputs.devel_prs in the summary step (route via env).
- Align the empty-suite checkout fallback with the resolute-qcom-devel default.

docs/PIPELINE.md: correct the pull_request_target rationale, document the
install-on-devel step and the residual credentialed-runner security note.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
@bjordiscollaku
Bjordis Collaku (bjordiscollaku) merged commit d907a88 into main Jul 11, 2026
9 checks passed
@bjordiscollaku
Bjordis Collaku (bjordiscollaku) deleted the feat/pr-build-pipeline branch July 17, 2026 03:30
Bjordis Collaku (bjordiscollaku) added a commit that referenced this pull request Jul 28, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR
into resolute-qcom-devel (the merge ref, build-only) via the reusable
build-kernel.yml on main. It lives on this branch because GitHub resolves
pull_request workflows from the PR base branch, not the default branch.

Depends on the workflow_call interface in #25;
do not merge until #25 lands on main.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
ximiali pushed a commit to ximiali/pkg-linux-qcom-canonical-new that referenced this pull request Jul 30, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR
into resolute-qcom-devel (the merge ref, build-only) via the reusable
build-kernel.yml on main. It lives on this branch because GitHub resolves
pull_request workflows from the PR base branch, not the default branch.

Depends on the workflow_call interface in qualcomm-linux#25;
do not merge until qualcomm-linux#25 lands on main.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
(cherry picked from commit 998080b)
github-actions Bot pushed a commit that referenced this pull request Aug 17, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR
into resolute-qcom-devel (the merge ref, build-only) via the reusable
build-kernel.yml on main. It lives on this branch because GitHub resolves
pull_request workflows from the PR base branch, not the default branch.

Depends on the workflow_call interface in #25;
do not merge until #25 lands on main.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
(cherry picked from commit 998080b)
github-actions Bot pushed a commit that referenced this pull request Sep 16, 2026
Adds .github/workflows/premerge-pr.yml: a pull_request check that builds every PR
into resolute-qcom-devel (the merge ref, build-only) via the reusable
build-kernel.yml on main. It lives on this branch because GitHub resolves
pull_request workflows from the PR base branch, not the default branch.

Depends on the workflow_call interface in #25;
do not merge until #25 lands on main.

Signed-off-by: Bjordis Collaku <bcollaku@qti.qualcomm.com>
(cherry picked from commit 998080b)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants