Registered a 3rd repo-scoped runner on bfe-mpc-0640 (label warden-sdk, bfe-mpc-0640-warden-sdk) per ADR-0004. It is offline pending the sudo-gated steps (service install + CPUQuota/MemoryMax cgroup cap + toolchain/python provisioning), documented in docs/ci-cd.md as a [maintainer] handoff. kernel-build stays dispatch-gated and passes JOBS=4 as a belt-and-braces resource bound. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017wB8KB3MMQztRDXCMCkPrf
2.7 KiB
2.7 KiB
CI/CD
.github/workflows/ci.yml — everything portable runs on GitHub-hosted
ubuntu-latest; only the heavy kernel build uses the self-hosted runner.
Jobs
| Job | Runner | What it does |
|---|---|---|
test |
ubuntu-latest | cargo test (sim + config-lint) + cargo-llvm-cov line coverage on sim; outputs passed/coverage. |
mcdc |
ubuntu-latest | 100% MC/DC enforced on every drivers/*/test (gcc-14 -fcondition-coverage). |
bench |
ubuntu-latest | Smoke-runs the sim micro-benchmarks; emits ns/op trend JSON. |
patches-apply |
ubuntu-latest | Fetches pristine linux-6.18.46 (cached, sha256-verified) and applies patches/* in order. |
kernel-build |
[self-hosted, warden-sdk] | build/build-kernel.sh → zImage + rv1106-warden.dtb, uploaded as an artifact. Dispatch-gated until the runner is fully provisioned (below). |
badges |
ubuntu-latest | Renders loc/tests/coverage shields on push to bringup ([skip ci] + paths-ignore loop guard). |
The self-hosted runner (bfe-mpc-0640)
A third repo-scoped runner instance on bfe-mpc-0640 (alongside flare and
flare-edge), registered with the label warden-sdk as
bfe-mpc-0640-warden-sdk, in ~/actions-runner-warden-sdk. The registration is
done; the following steps need user's sudo on 0640 and are not automatable
from the dev box:
- Install as a service (persistence):
cd ~/actions-runner-warden-sdk && sudo ./svc.sh install user && sudo ./svc.sh start. Until then the runner is offline andkernel-buildonly runs when dispatched against an online runner. - Resource cap (protect the shared host): a drop-in at
/etc/systemd/system/actions.runner.bfe-noah-warden-sdk.*.service.d/*.confwithCPUQuota=400%+MemoryMax=6G, thensudo systemctl daemon-reload. The build inherits that cgroup. (The workflow also passesJOBS=4as a belt-and-braces bound.) - Kernel cross toolchain:
build-kernel.shneeds the arm cross compiler on PATH — setSDK_TCto the dir holdingarm-rockchip830-linux-uclibcgnueabihf-*(the Luckfox SDK toolchain, as flare-edge's runner has), or installgcc-arm-linux-gnueabihfand passCROSS_COMPILE=arm-linux-gnueabihf-(the kernel is freestanding, so a generic arm cross compiler links it). python(not python3): the kernel build calls barepython; provide a project-local venv or apython→python3shim on the runner's PATH.
Host build deps (sudo): dtc bc flex bison libssl-dev (already present on 0640).
Badges
Static shields SVGs are committed by the badges job (private repo can't use
dynamic shields). The GitHub-native ci.yml status badge works live regardless.