Build ONIE (kvm_x86_64) #9
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Build ONIE (kvm_x86_64) | |
| # Builds the generic amd64 ONIE image for the kvm_x86_64 target, intended | |
| # to run as a VM under KVM/QEMU. The build follows the upstream-recommended | |
| # containerized flow (see contrib/build-env and machine/kvm_x86_64/INSTALL), | |
| # with secure boot disabled so no signing keys are required. | |
| on: | |
| workflow_dispatch: | |
| push: | |
| paths: | |
| - 'build-config/**' | |
| - 'machine/kvm_x86_64/**' | |
| - '.github/workflows/build-onie.yml' | |
| - '.github/onie-build/**' | |
| pull_request: | |
| paths: | |
| - 'build-config/**' | |
| - 'machine/kvm_x86_64/**' | |
| - '.github/workflows/build-onie.yml' | |
| - '.github/onie-build/**' | |
| # Cancel an in-progress run when a newer commit is pushed to the same ref, | |
| # so stacked pushes don't pile up concurrent builds. | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.ref }} | |
| cancel-in-progress: true | |
| jobs: | |
| build: | |
| name: Build kvm_x86_64 | |
| runs-on: ubuntu-latest | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@v4 | |
| - name: Set up Docker Buildx | |
| uses: docker/setup-buildx-action@v3 | |
| - name: Determine host UID/GID | |
| id: ids | |
| run: | | |
| echo "uid=$(id -u)" >> "$GITHUB_OUTPUT" | |
| echo "gid=$(id -g)" >> "$GITHUB_OUTPUT" | |
| - name: Build the ONIE build-environment image | |
| uses: docker/build-push-action@v6 | |
| with: | |
| context: .github/onie-build | |
| tags: onie-build-env:latest | |
| build-args: | | |
| UID=${{ steps.ids.outputs.uid }} | |
| GID=${{ steps.ids.outputs.gid }} | |
| load: true | |
| cache-from: type=gha | |
| cache-to: type=gha,mode=max | |
| - name: Disable secure boot in the kernel config | |
| # The kvm_x86_64 kernel config defaults to expecting signing keys. | |
| # The repo ships a config-insecure variant for non-secure-boot builds. | |
| run: cp machine/kvm_x86_64/kernel/config-insecure machine/kvm_x86_64/kernel/config | |
| # Cache the crosstool-NG cross toolchain -- the long pole of a cold | |
| # build. We must cache the entire stamp chain, not just the final | |
| # toolchain, or ONIE's make will rebuild it: a missing download stamp | |
| # (build/download) or project stamp (build/stamp-project) forces the | |
| # chain to re-run from the top. | |
| # | |
| # build/stamp-project -- top-of-chain project stamp | |
| # build/download -- toolchain source tarballs + download stamps | |
| # build/crosstool-ng -- the crosstool-NG tool + its build stamps | |
| # build/x-tools -- the installed cross toolchain + its stamps | |
| # | |
| # The key is tied to every input that can change the toolchain -- | |
| # including the Dockerfile, since it defines the compiler/host | |
| # environment the toolchain is built in. No loose restore-keys: any | |
| # input change forces a clean rebuild rather than restoring a | |
| # mismatched toolchain. | |
| - name: Restore cross-toolchain cache | |
| id: xtools-cache | |
| uses: actions/cache/restore@v4 | |
| with: | |
| path: | | |
| build/stamp-project | |
| build/download | |
| build/crosstool-ng | |
| build/x-tools | |
| # v2: cache the full stamp chain (added build/stamp-project + | |
| # build/download); bump to bypass v1 caches that lack them. | |
| key: onie-xtools-v2-kvm_x86_64-${{ hashFiles('build-config/make/xtools.make', 'build-config/make/crosstool-ng.make', 'build-config/make/compiler.make', 'build-config/conf/crosstool/**', 'patches/crosstool-NG/**', '.github/onie-build/Dockerfile') }} | |
| # ONIE drives its build with stamp files compared by mtime. A fresh | |
| # checkout gives every repo source file a current mtime, which is newer | |
| # than the restored stamps -- so make would consider the toolchain | |
| # stale and rebuild it (e.g. build/.../.config depends on the | |
| # checked-out conf/crosstool config). A cache hit means the key | |
| # matched, i.e. every toolchain input is unchanged and the restored | |
| # toolchain is valid, so bump the restored artifacts ahead of the | |
| # checkout to make "make xtools" a genuine no-op. | |
| - name: Mark restored toolchain up to date | |
| if: steps.xtools-cache.outputs.cache-hit == 'true' | |
| run: find build/stamp-project build/download build/crosstool-ng build/x-tools -exec touch {} + | |
| - name: Build cross toolchain | |
| run: | | |
| docker run --rm --privileged \ | |
| -v "${PWD}:/onie" \ | |
| onie-build-env \ | |
| bash -lc 'cd build-config && make -j"$(nproc)" \ | |
| MACHINE=kvm_x86_64 \ | |
| SECURE_BOOT_ENABLE=no \ | |
| SECURE_BOOT_EXT=no \ | |
| SECURE_GRUB=no \ | |
| xtools' | |
| # Save only on a cache miss, and only after the toolchain build above | |
| # succeeded (default if: success()), so a broken toolchain is never | |
| # cached. Running before the full build means a later-stage failure | |
| # still preserves the toolchain for the next run. | |
| - name: Save cross-toolchain cache | |
| if: steps.xtools-cache.outputs.cache-hit != 'true' | |
| uses: actions/cache/save@v4 | |
| with: | |
| path: | | |
| build/stamp-project | |
| build/download | |
| build/crosstool-ng | |
| build/x-tools | |
| key: ${{ steps.xtools-cache.outputs.cache-primary-key }} | |
| - name: Build ONIE | |
| run: | | |
| docker run --rm --privileged \ | |
| -v "${PWD}:/onie" \ | |
| onie-build-env \ | |
| bash -lc 'cd build-config && make -j"$(nproc)" \ | |
| MACHINE=kvm_x86_64 \ | |
| SECURE_BOOT_ENABLE=no \ | |
| SECURE_BOOT_EXT=no \ | |
| SECURE_GRUB=no \ | |
| all recovery-iso' |