Files
bfe-core1106-sdk/docs/ci-cd.md
T
BFE EngineeringandClaude Fable 5 5155224594 public-readiness: scrub internal details, split licensing, hosted kernel-build
Preparing the repo to go public (ADR-0007):

- CI: kernel-build moves from the self-hosted runner to ubuntu-latest
  (installs its own cross toolchain + qemu, caches the pristine tarball).
  On a public repo a registered self-hosted runner is reachable from
  approved fork-PR workflows — i.e. arbitrary code on private
  infrastructure — and the build never actually needed the SDK host.
  ADR-0004 marked superseded-in-part; docs/ci-cd.md rewritten (site
  specifics now live only in the private deployment log).
- Licensing: LICENSE gains the GPL-2.0 carve-out for patches/ and the
  kernel source excerpts (Linux derivatives; per-driver provenance was
  already tracked in PROVENANCE.md); patches/README.md states it too.
- Scrubbed from the tip: bench-unit dev credentials and its gadget IP
  (m2-boot notes), the site AP SSID+BSSID and a neighboring AP's BSSID
  and the device WLAN MAC (wifi bring-up evidence — BSSIDs are
  geolocatable), the runner mesh IP. NOTE: these remain in git history;
  decision on a pre-publication history rewrite is separate.
- Emoji cleanup across 21 tracked files (kernel port docs, review report,
  enforce-mcdc.sh) per repo text conventions: status marks became
  [x]/[wip]/[ ]/OK plain text.
- "[maintainer]-gated" process phrasing normalized to "maintainer-gated"
  (attributions in dated evidence docs kept).

Verified: zero emojis tracked; scrub grep clean; patches carry no internal
references; ci.yml parses; shellcheck unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018HUayid7W5w7jBdb9Rrj1K
2026-08-30 07:25:57 -06:00

2.0 KiB

CI/CD

.github/workflows/ci.yml — every job runs on GitHub-hosted ubuntu-latest. No self-hosted runner is (or may be) reachable from this repo's workflows: the repo is public, and a fork PR that gets one approved run could otherwise execute code on private infrastructure (ADR-0007).

Jobs

Job Runner What it does
test ubuntu-latest cargo test (sim + config-lint + qemu/rs485-bridge) + cargo-llvm-cov line coverage on sim; outputs passed/coverage.
mcdc ubuntu-latest 100% MC/DC enforced on every drivers/*/test (gcc-14 -fcondition-coverage).
bench ubuntu-latest Smoke-runs the sim + rs485-bridge micro-benchmarks; emits ns/op trend JSON.
patches-apply ubuntu-latest Fetches pristine linux-6.18.46 (cached, sha256-verified) and applies patches/* in order.
qemu-tools ubuntu-latest shellcheck on qemu/**.sh; builds the initramfs (pinned busybox) and the A/B disk image.
kernel-build ubuntu-latest, dispatch-only apt-installs the cross toolchain + qemu, build/build-kernel.shzImage + rv1106-warden.dtb, QEMU -M virt boot smoke (fail-closed), artifact upload (best-effort). Trigger: gh workflow run ci.yml.
prune-artifacts ubuntu-latest, dispatch-only Deletes kernel-rv1106 artifacts beyond the newest 3.
badges ubuntu-latest Renders loc/tests/coverage shields on push to main ([skip ci] + paths-ignore loop guard).

History: the self-hosted runner (retired)

kernel-build originally ran on a repo-scoped self-hosted runner (ADR-0004, 2026-08-25, verified end-to-end) because hosted minutes were metered on the private repo. Going public made hosted minutes free and made a self-hosted registration a liability, so ADR-0007 moved the job to ubuntu-latest and retired the registration. Site-specific install records for that runner live in our private deployment log, not here.

Badges

Static shields SVGs are committed by the badges job. The GitHub-native ci.yml status badge works live regardless.