* [isar-cip-core][PATCH v2 0/2] Enable debian forky build & test support @ 2026-07-28 8:55 Shivanand.Kunijadar 2026-07-28 8:55 ` [isar-cip-core][PATCH v2 1/2] Enable the support of Debian forky based builds Shivanand.Kunijadar 2026-07-28 8:55 ` [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky Shivanand.Kunijadar 0 siblings, 2 replies; 8+ messages in thread From: Shivanand.Kunijadar @ 2026-07-28 8:55 UTC (permalink / raw) To: cip-dev, jan.kiszka Cc: Shivanand Kunijadar, kumar.dinesh.h95, kazuhiro.hayashi.f74 From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> This patch series adds the debian forky based image build & CI test support. It enables SWUpdate, secure boot, security tests in LAVA and RB in gitlab CI. NOTE: - The existing .reproducible-check-ci.yml is updated to support forky images reproducibility check. No need to add the exta scheduled pipeline for forky, the current scheduled pipeline covers both trixie and forky. The forky builds and RB tests are kept with allowed failure option as true. - The CI variable CI_RUN_UNSTABLE_FORKY is changed to CI_RUN_UNSTABLE, however CI_RUN_UNSTABLE_SID is not changed in this patch series, will update in a separate patch as it is not related to this series. - Updated authors list for .gitlab-ci.yml & .reproducible-check-ci.yml Shivanand Kunijadar (2): Enable the support of Debian forky based builds Enable CI image build and test support for forky .gitlab-ci.yml | 148 ++++++++++++++++++ .reproducible-check-ci.yml | 72 +++++++++ Kconfig | 4 + conf/distro/cip-core-forky.conf | 13 ++ kas/opt/forky.yml | 15 ++ .../files/forky/PkKek-1-snakeoil.key | 30 ++++ .../files/forky/PkKek-1-snakeoil.pem | 23 +++ .../swupdate-certificates/files/forky | 1 + start-qemu.sh | 2 + 9 files changed, 308 insertions(+) create mode 100644 conf/distro/cip-core-forky.conf create mode 100644 kas/opt/forky.yml create mode 100644 recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.key create mode 100644 recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.pem create mode 120000 recipes-devtools/swupdate-certificates/files/forky -- 2.39.5 ^ permalink raw reply [flat|nested] 8+ messages in thread
* [isar-cip-core][PATCH v2 1/2] Enable the support of Debian forky based builds 2026-07-28 8:55 [isar-cip-core][PATCH v2 0/2] Enable debian forky build & test support Shivanand.Kunijadar @ 2026-07-28 8:55 ` Shivanand.Kunijadar 2026-07-28 8:55 ` [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky Shivanand.Kunijadar 1 sibling, 0 replies; 8+ messages in thread From: Shivanand.Kunijadar @ 2026-07-28 8:55 UTC (permalink / raw) To: cip-dev, jan.kiszka Cc: Shivanand Kunijadar, kumar.dinesh.h95, kazuhiro.hayashi.f74 From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> The .key & .pem files are addded using below .deb package, https://snapshot.debian.org/file/d32d11a5aacbf5685b81e8176a27a6918e9b55fb/ovmf-generic_2025.11-5_all.deb Signed-off-by: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> --- Kconfig | 4 +++ conf/distro/cip-core-forky.conf | 13 ++++++++ kas/opt/forky.yml | 15 ++++++++++ .../files/forky/PkKek-1-snakeoil.key | 30 +++++++++++++++++++ .../files/forky/PkKek-1-snakeoil.pem | 23 ++++++++++++++ .../swupdate-certificates/files/forky | 1 + start-qemu.sh | 2 ++ 7 files changed, 88 insertions(+) create mode 100644 conf/distro/cip-core-forky.conf create mode 100644 kas/opt/forky.yml create mode 100644 recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.key create mode 100644 recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.pem create mode 120000 recipes-devtools/swupdate-certificates/files/forky diff --git a/Kconfig b/Kconfig index 438234c..19f8e24 100644 --- a/Kconfig +++ b/Kconfig @@ -238,6 +238,9 @@ config DEBIAN_BOOKWORM config DEBIAN_TRIXIE bool "trixie (13)" +config DEBIAN_FORKY + bool "forky (14)" + config DEBIAN_SID bool "Sid (Unstable)" @@ -249,6 +252,7 @@ config KAS_INCLUDE_DEBIAN default "kas/opt/bullseye.yml" if DEBIAN_BULLSEYE default "kas/opt/bookworm.yml" if DEBIAN_BOOKWORM default "kas/opt/trixie.yml" if DEBIAN_TRIXIE + default "kas/opt/forky.yml" if DEBIAN_FORKY default "kas/opt/sid.yml" if DEBIAN_SID comment "Image features" diff --git a/conf/distro/cip-core-forky.conf b/conf/distro/cip-core-forky.conf new file mode 100644 index 0000000..7a868ce --- /dev/null +++ b/conf/distro/cip-core-forky.conf @@ -0,0 +1,13 @@ +# +# CIP Core, generic profile +# +# Copyright (c) Toshiba Corporation, 2026 +# +# Authors: +# Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> +# +# SPDX-License-Identifier: MIT +# + +require conf/distro/debian-forky.conf +require cip-core-common.inc diff --git a/kas/opt/forky.yml b/kas/opt/forky.yml new file mode 100644 index 0000000..6c4fcdc --- /dev/null +++ b/kas/opt/forky.yml @@ -0,0 +1,15 @@ +# +# CIP Core, generic profile +# +# Copyright (c) Toshiba Corporation, 2026 +# +# Authors: +# Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> +# +# SPDX-License-Identifier: MIT +# + +header: + version: 14 + +distro: cip-core-forky diff --git a/recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.key b/recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.key new file mode 100644 index 0000000..dd7f492 --- /dev/null +++ b/recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.key @@ -0,0 +1,30 @@ +-----BEGIN ENCRYPTED PRIVATE KEY----- +MIIFHDBOBgkqhkiG9w0BBQ0wQTApBgkqhkiG9w0BBQwwHAQIs4RXCLmGLJgCAggA +MAwGCCqGSIb3DQIJBQAwFAYIKoZIhvcNAwcECHer6014IEhGBIIEyO8O2zL8CJwV +auQpWLJsMMWxu2aSh1WadX9+rg+O61mukuS4rQSH5shMQ2krZZKzyXx0q8+2AySD +EtDXwhLvep60gUxOoNqK1+l3AxSFfIGOY8NC6yW67VX+G09ajWpgHj3ox63VRW8v +6mA8TFWYbOIwB8J7ScF4NszVwyiUnW13oKi7svoBM3LYYG2IMvre+gOvyMGfM8uv +X3txcYqAjhRV6n7vGo9LRLIIRSPKzaJbm/W7nT38LRUJP8JMSQUOPKgeEwQvOTVZ ++1kd7WeaGZrjagTDM4yhBjpOmB3D8aeT6xkjBlUwuddPzbdi0N7GrU520RcJMjxt +JMyOgabHKUKmPTX4m0ZCKi2jSILi7/6fBF+TZDxpakLwAwpTzm6kXArXb6AYtTEX +GPihB4O69ZgEc90jp3EnZt7HtKZn1HTbPNQAlWgvESgJ7hWHnTlM5Obqnyb78tj5 +VdcOfTSQRYmw4Rh/lSUX0vQLhdmYSVLiMFFvT4IepXZgQ6McIdcvqoVrPgr0HoVz +5YILZdmbs80VcgYL853lMfQ84kRwUcw8jNyz7mBK7V7rE5QhaF5lunZ/R41ZRXRy +1ys1rNvLPvtOq/K51+A9U+h5lLM9LjeoOR+IUk2Vg4aIap+Z+lxbImH0gcJTrpem +ctA/2sBjLN7w811EjB/Tlu2awzbsKLpIDFVGHiGBI2zb41gtPd2RkijmiZab6nuM +ETg4ad3GscMoa++01oX/lrnVe386ECSjurmThb7I01eTNZrBlNsLyBeFzlEIEoBR +TqUXHLiDACxzL6U4vWzdnvVrCOW9fwvJJqChj7Wy822w2LXxVhOryNujBmZCmOht +mgDaJ15QiF+DACcX6VoBbm/462z+9Skxa0DqGwGzMOD5HldwvQSyZSykk/BzGFWP +rXfLYoMjN+dgA/yNfem64ayGsmoPUAjnsE4YasD58UVO0XwwtdMGJSOVmkdyWMcM +t+lN74kX/gmIvciK06N6prBfowgBEIJ6ev2dzlydSN8rGORmQ+OFzjP14rT0O+1Q +O48yR2ZZ9jl4YPUKSFJ3EUc/Qt9vO+chNiNYSy6TABGXur0WWiDvGURG9K5fWTqq +U2KydSRoYD5iF0caOgMZecNhZV+4CX927j3XuuKKx49qTAt3WMtmJ/UQFHMtQ833 +XDFWHpEKDImfHfyiB1f8bOmqYmPuE6Shup0UMJsMFel4QVJM0Jn9+wHw/0qqPiS3 +a769S/u9U2dfyZY5PfymY8UjFRMDtLaUoJSRaGp6RNc6LynuMMKdzho0GwvL3+m9 +xKLDbbks8hVdmtcxxDKiio+F0hp3yc/2PyA/VGAlARiGp7876WTCZox9Bwnf6lkS +k9eYLSabe/r3Ag1SbWEGpFk3VO37qCyfp2xTfrHXK1ZJlvFwj3FFSprUaMrV+81K +FCEcSozXpVsQ7e7d11A7S8rTbtp09Q/J2oxyR0A9lk/ia5Qd/xwbPl4QJcWK2Jar +K3yFK8VrUNib7CjI1kdB479KIllD8oK6druBkzwGzFxDtcl47RlfkqW96XSQT7x/ +h/YKSLcpMx9x9TJd2GDKj2t4oE9eGTBC0YbdH+HJNSrjEsWkjgY6Uw++S6VzKvQZ +DDsMJfxwcChc2zKRou+BFA== +-----END ENCRYPTED PRIVATE KEY----- diff --git a/recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.pem b/recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.pem new file mode 100644 index 0000000..7cd2487 --- /dev/null +++ b/recipes-devtools/secure-boot-secrets/files/forky/PkKek-1-snakeoil.pem @@ -0,0 +1,23 @@ +-----BEGIN CERTIFICATE----- +MIID1zCCAr+gAwIBAgIUDMG7xGGEPj+ABvbflim0PNb/loowDQYJKoZIhvcNAQEL +BQAwejELMAkGA1UEBhMCVVMxETAPBgNVBAgMCENvbG9yYWRvMRUwEwYDVQQHDAxG +b3J0IENvbGxpbnMxETAPBgNVBAoMCFNuYWtlT2lsMS4wLAYDVQQDDCVTbmFrZU9p +bCBUZXN0IEtleSBmb3IgRUZJIFNlY3VyZSBCb290MCAXDTIzMDUxOTIzMTE0NVoY +DzIwNTMwNTE3MjMxMTQ1WjB6MQswCQYDVQQGEwJVUzERMA8GA1UECAwIQ29sb3Jh +ZG8xFTATBgNVBAcMDEZvcnQgQ29sbGluczERMA8GA1UECgwIU25ha2VPaWwxLjAs +BgNVBAMMJVNuYWtlT2lsIFRlc3QgS2V5IGZvciBFRkkgU2VjdXJlIEJvb3QwggEi +MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDIi65d6LmojD5S9q8vE/LI2HHQ +boiO5/1KrFVc6kpxD6XdkJwpBoItYIfSls9CPnzvNWOAxR3hIeBd1U/prAPPxvQ1 +wuDLMXfWkcGaYHfPnme/YluAjnpuLH1MQcumgOzj5xYBvZZk+RbytX/phH7FW4Tx ++L1oBYnsfh3BSE/NTtEEHV1nXAXpa/dvyefWMlrlbwjfM5362lZzM6yrJGcOcWEy +I66UYCIVO2Yhe/ZVF5B/tPGtd2oACz11xLeqLPM1WBjlekAG2Zi7UCPIvDCpdn5u +Vna2ZRQmJyDDdh0Ja2VMC19dkMd/5nOAI21O+FvYPOkBWYX8f4DzDyVQlmIFAgMB +AAGjUzBRMB0GA1UdDgQWBBRjuNXuXfh7mi8I3eTboeYGyFTa2zAfBgNVHSMEGDAW +gBRjuNXuXfh7mi8I3eTboeYGyFTa2zAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3 +DQEBCwUAA4IBAQBBxlfo6MxBN44mXBIhE/QUbJZ+bo/Vrqv2DIZqOlV5+Sk6KnK8 +X9Rz2IJwoqLjB6cW9yInk5P/QS45880K1fDT/lu5/2U64i3l1ZFK75qLDCn4/khF +birV2U6LBZpxLe3UvXk3xZMoUPzvT2rhrsf78G0pSmAnP8li8Co8F6hTjQzB8IgC +DpYVATCoWBH6GhudtjUp+CJSyGApdL+HKX6i6oD7vutvWYBf0Hx5r1NrqIv31Y4V +bhwvK5zajFamj/VYeVy7/roqD06hNF1ImhsuBOqoJlKu+cHMGN9DOJqjGup1T9aI +2dpEOK5vbKXFrox/yCLgXmUkdwZ3BK4lcxCq +-----END CERTIFICATE----- diff --git a/recipes-devtools/swupdate-certificates/files/forky b/recipes-devtools/swupdate-certificates/files/forky new file mode 120000 index 0000000..2719d00 --- /dev/null +++ b/recipes-devtools/swupdate-certificates/files/forky @@ -0,0 +1 @@ +../../secure-boot-secrets/files/forky \ No newline at end of file diff --git a/start-qemu.sh b/start-qemu.sh index d12fa23..2fb9c9c 100755 --- a/start-qemu.sh +++ b/start-qemu.sh @@ -45,6 +45,8 @@ if [ -z "${DISTRO_RELEASE}" ]; then DISTRO_RELEASE="bookworm" elif grep -s -q "DEBIAN_TRIXIE: true" .config.yaml; then DISTRO_RELEASE="trixie" + elif grep -s -q "DEBIAN_FORKY: true" .config.yaml; then + DISTRO_RELEASE="forky" elif grep -s -q "DEBIAN_SID: true" .config.yaml; then DISTRO_RELEASE="sid" else -- 2.39.5 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky 2026-07-28 8:55 [isar-cip-core][PATCH v2 0/2] Enable debian forky build & test support Shivanand.Kunijadar 2026-07-28 8:55 ` [isar-cip-core][PATCH v2 1/2] Enable the support of Debian forky based builds Shivanand.Kunijadar @ 2026-07-28 8:55 ` Shivanand.Kunijadar 2026-07-28 15:29 ` Jan Kiszka 1 sibling, 1 reply; 8+ messages in thread From: Shivanand.Kunijadar @ 2026-07-28 8:55 UTC (permalink / raw) To: cip-dev, jan.kiszka Cc: Shivanand Kunijadar, kumar.dinesh.h95, kazuhiro.hayashi.f74 From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> Keep these jobs as scheduled and can be scheduled to run every week just to monitor and fix if there are any issues. Also set allow_failure:true for these jobs as forky is not officially released and there will always be some build & test issues. It includes SWUpdate, secure boot & RB tests. Signed-off-by: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> --- .gitlab-ci.yml | 148 +++++++++++++++++++++++++++++++++++++ .reproducible-check-ci.yml | 72 ++++++++++++++++++ 2 files changed, 220 insertions(+) diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index b53def4..b15c5da 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -8,6 +8,7 @@ # Jan Kiszka <jan.kiszka@siemens.com> # Quirin Gylstorff <quirin.gylstorff@siemens.com> # Nobuhiro Iwamatsu <nobuhiro1.iwamatsu@toshiba.co.jp> +# Shivanand Kunijadar <shivanand.kunijadar@toshiba-tsip.com> # # SPDX-License-Identifier: MIT # @@ -63,6 +64,7 @@ default: - if [ "${release}" = "bullseye" ]; then base_yaml="${base_yaml}:kas/opt/bullseye.yml"; fi - if [ "${release}" = "bookworm" ]; then base_yaml="${base_yaml}:kas/opt/bookworm.yml"; fi - if [ "${release}" = "trixie" ]; then base_yaml="${base_yaml}:kas/opt/trixie.yml"; fi + - if [ "${release}" = "forky" ]; then base_yaml="${base_yaml}:kas/opt/forky.yml"; fi - if [ "${release}" = "sid" ]; then base_yaml="${base_yaml}:kas/opt/sid.yml"; fi - if [ "${encrypt}" = "enable" ]; then base_yaml="${base_yaml}:kas/opt/encrypt-data.yml"; fi - if [ "${factory_reset}" = "enable" ]; then base_yaml="${base_yaml}:kas/opt/factory-reset.yml"; fi @@ -399,6 +401,57 @@ build:qemu-arm-base-sid: separate_home_partition: enable deploy: enable +# forky image builds +.build_base_forky: + extends: + - .build_base + rules: + - if: $CI_COMMIT_TAG + when: never + - if: '$CI_PIPELINE_SOURCE == "schedule" && $CI_RUN_UNSTABLE' + - if: $CI_COMMIT_BRANCH != "master" + when: never + allow_failure: true + +build:qemu-amd64-base-forky: + extends: + - .build_base_forky + variables: + target: qemu-amd64 + use_rt: disable + release: forky + extension: security + security_test: enable + build_updates: enable + separate_home_partition: enable + deploy: enable + +build:qemu-arm64-base-forky: + extends: + - .build_base_forky + variables: + target: qemu-arm64 + use_rt: disable + release: forky + extension: security + security_test: enable + build_updates: enable + separate_home_partition: enable + deploy: enable + +build:qemu-arm-base-forky: + extends: + - .build_base_forky + variables: + target: qemu-arm + extension: security + security_test: enable + use_rt: disable + release: forky + build_updates: enable + separate_home_partition: enable + deploy: enable + .test-cip-core: stage: test image: $CI_REGISTRY_IMAGE/lavacli @@ -764,6 +817,101 @@ test:qemu-arm-IEC-sid: test_function: IEC iec_test_timeout: 40 +# Tests for forky images +.test-cip-core-forky: + extends: + - .test-cip-core + rules: + - if: $CI_COMMIT_TAG + when: never + - if: '$CI_PIPELINE_SOURCE == "schedule" && $CI_RUN_UNSTABLE' + - if: $CI_COMMIT_BRANCH != "master" + when: never + allow_failure: true + +test:qemu-amd64-swupdate-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-amd64-base-forky"] + variables: + target: qemu-amd64 + release: forky + test_function: swupdate + +test:qemu-arm64-swupdate-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-arm64-base-forky"] + variables: + target: qemu-arm64 + release: forky + test_function: swupdate + +test:qemu-arm-swupdate-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-arm-base-forky"] + variables: + target: qemu-arm + release: forky + test_function: swupdate + +test:qemu-amd64-secure-boot-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-amd64-base-forky"] + variables: + target: qemu-amd64 + release: forky + test_function: secure-boot + +test:qemu-arm64-secure-boot-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-arm64-base-forky"] + variables: + target: qemu-arm64 + release: forky + test_function: secure-boot + +test:qemu-arm-secure-boot-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-arm-base-forky"] + variables: + target: qemu-arm + release: forky + test_function: secure-boot + +test:qemu-amd64-IEC-forky: + extends: + - .test-cip-core-forky + variables: + target: qemu-amd64 + release: forky + test_function: IEC + iec_test_timeout: 40 + +test:qemu-arm64-IEC-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-arm64-base-forky"] + variables: + target: qemu-arm64 + release: forky + test_function: IEC + iec_test_timeout: 40 + +test:qemu-arm-IEC-forky: + extends: + - .test-cip-core-forky + needs: ["build:qemu-arm-base-forky"] + variables: + target: qemu-arm + release: forky + test_function: IEC + iec_test_timeout: 40 + cve-checks: stage: cve-check needs: [] diff --git a/.reproducible-check-ci.yml b/.reproducible-check-ci.yml index fb24188..1246a64 100644 --- a/.reproducible-check-ci.yml +++ b/.reproducible-check-ci.yml @@ -5,6 +5,8 @@ # # Authors: # Venkata Pyla <venkata.pyla@toshiba-tsip.com> +# Adithya Balakumar <adithya.balakumar@toshiba-tsip.com> +# Shivanand Kunijadar <shivanand.kunijadar@toshiba-tsip.com> # # SPDX-License-Identifier: MIT # @@ -130,6 +132,39 @@ build:x86-uefi-repro-build: variables: target: x86-uefi +# repro build for debian forky +build:qemu-amd64-repro-build-forky: + extends: + - .repro-build + variables: + target: qemu-amd64 + release: forky + allow_failure: true + +build:qemu-arm64-repro-build-forky: + extends: + - .repro-build + variables: + target: qemu-arm64 + release: forky + allow_failure: true + +build:qemu-arm-repro-build-forky: + extends: + - .repro-build + variables: + target: qemu-arm + release: forky + allow_failure: true + +build:x86-uefi-repro-build-forky: + extends: + - .repro-build + variables: + target: x86-uefi + release: forky + allow_failure: true + # repro build test test:qemu-amd64-repro-test: extends: @@ -166,3 +201,40 @@ test:x86-uefi-repro-test: variables: target: x86-uefi needs: ["build:x86-uefi-repro-build"] + +# repro build test for debian forky +test:qemu-amd64-repro-test-forky: + extends: + - .repro-test + variables: + target: qemu-amd64 + release: forky + allow_failure: true + needs: ["build:qemu-amd64-repro-build-forky"] + +test:qemu-arm64-repro-test-forky: + extends: + - .repro-test + variables: + target: qemu-arm64 + release: forky + allow_failure: true + needs: ["build:qemu-arm64-repro-build-forky"] + +test:qemu-arm-repro-test-forky: + extends: + - .repro-test + variables: + target: qemu-arm + release: forky + allow_failure: true + needs: ["build:qemu-arm-repro-build-forky"] + +test:x86-uefi-repro-test-forky: + extends: + - .repro-test + variables: + target: x86-uefi + release: forky + allow_failure: true + needs: ["build:x86-uefi-repro-build-forky"] -- 2.39.5 ^ permalink raw reply related [flat|nested] 8+ messages in thread
* Re: [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky 2026-07-28 8:55 ` [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky Shivanand.Kunijadar @ 2026-07-28 15:29 ` Jan Kiszka 2026-07-29 4:26 ` Kunijadar Shivanand 0 siblings, 1 reply; 8+ messages in thread From: Jan Kiszka @ 2026-07-28 15:29 UTC (permalink / raw) To: Shivanand.Kunijadar, cip-dev; +Cc: kumar.dinesh.h95, kazuhiro.hayashi.f74 On 28.07.26 10:55, Shivanand.Kunijadar@toshiba-tsip.com wrote: > From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> > > Keep these jobs as scheduled and can be scheduled to run every week > just to monitor and fix if there are any issues. > Also set allow_failure:true for these jobs as forky is not officially > released and there will always be some build & test issues. > > It includes SWUpdate, secure boot & RB tests. > > Signed-off-by: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> > --- > .gitlab-ci.yml | 148 +++++++++++++++++++++++++++++++++++++ > .reproducible-check-ci.yml | 72 ++++++++++++++++++ > 2 files changed, 220 insertions(+) > > diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml > index b53def4..b15c5da 100644 > --- a/.gitlab-ci.yml > +++ b/.gitlab-ci.yml > @@ -8,6 +8,7 @@ > # Jan Kiszka <jan.kiszka@siemens.com> > # Quirin Gylstorff <quirin.gylstorff@siemens.com> > # Nobuhiro Iwamatsu <nobuhiro1.iwamatsu@toshiba.co.jp> > +# Shivanand Kunijadar <shivanand.kunijadar@toshiba-tsip.com> > # > # SPDX-License-Identifier: MIT > # > @@ -63,6 +64,7 @@ default: > - if [ "${release}" = "bullseye" ]; then base_yaml="${base_yaml}:kas/opt/bullseye.yml"; fi > - if [ "${release}" = "bookworm" ]; then base_yaml="${base_yaml}:kas/opt/bookworm.yml"; fi > - if [ "${release}" = "trixie" ]; then base_yaml="${base_yaml}:kas/opt/trixie.yml"; fi > + - if [ "${release}" = "forky" ]; then base_yaml="${base_yaml}:kas/opt/forky.yml"; fi > - if [ "${release}" = "sid" ]; then base_yaml="${base_yaml}:kas/opt/sid.yml"; fi > - if [ "${encrypt}" = "enable" ]; then base_yaml="${base_yaml}:kas/opt/encrypt-data.yml"; fi > - if [ "${factory_reset}" = "enable" ]; then base_yaml="${base_yaml}:kas/opt/factory-reset.yml"; fi > @@ -399,6 +401,57 @@ build:qemu-arm-base-sid: > separate_home_partition: enable > deploy: enable > > +# forky image builds > +.build_base_forky: > + extends: > + - .build_base > + rules: > + - if: $CI_COMMIT_TAG > + when: never > + - if: '$CI_PIPELINE_SOURCE == "schedule" && $CI_RUN_UNSTABLE' I meant we should migrate both forky and sid under this one CI_RUN_UNSTABLE variable. Now we would still have two of them and would need to set them both in the pipeline schedule. Jan -- Siemens AG, Foundational Technologies Linux Expert Center ^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky 2026-07-28 15:29 ` Jan Kiszka @ 2026-07-29 4:26 ` Kunijadar Shivanand 2026-08-03 9:47 ` Kunijadar Shivanand 0 siblings, 1 reply; 8+ messages in thread From: Kunijadar Shivanand @ 2026-07-29 4:26 UTC (permalink / raw) To: cip-dev [-- Attachment #1: Type: text/plain, Size: 2898 bytes --] On Tue, Jul 28, 2026 at 08:29 AM, Jan Kiszka wrote: > > On 28.07.26 10:55, Shivanand.Kunijadar@toshiba-tsip.com wrote: > >> From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> >> >> Keep these jobs as scheduled and can be scheduled to run every week >> just to monitor and fix if there are any issues. >> Also set allow_failure:true for these jobs as forky is not officially >> released and there will always be some build & test issues. >> >> It includes SWUpdate, secure boot & RB tests. >> >> Signed-off-by: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> >> --- >> .gitlab-ci.yml | 148 +++++++++++++++++++++++++++++++++++++ >> .reproducible-check-ci.yml | 72 ++++++++++++++++++ >> 2 files changed, 220 insertions(+) >> >> diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml >> index b53def4..b15c5da 100644 >> --- a/.gitlab-ci.yml >> +++ b/.gitlab-ci.yml >> @@ -8,6 +8,7 @@ >> # Jan Kiszka <jan.kiszka@siemens.com> >> # Quirin Gylstorff <quirin.gylstorff@siemens.com> >> # Nobuhiro Iwamatsu <nobuhiro1.iwamatsu@toshiba.co.jp> >> +# Shivanand Kunijadar <shivanand.kunijadar@toshiba-tsip.com> >> # >> # SPDX-License-Identifier: MIT >> # >> @@ -63,6 +64,7 @@ default: >> - if [ "${release}" = "bullseye" ]; then >> base_yaml="${base_yaml}:kas/opt/bullseye.yml"; fi >> - if [ "${release}" = "bookworm" ]; then >> base_yaml="${base_yaml}:kas/opt/bookworm.yml"; fi >> - if [ "${release}" = "trixie" ]; then >> base_yaml="${base_yaml}:kas/opt/trixie.yml"; fi >> + - if [ "${release}" = "forky" ]; then >> base_yaml="${base_yaml}:kas/opt/forky.yml"; fi >> - if [ "${release}" = "sid" ]; then >> base_yaml="${base_yaml}:kas/opt/sid.yml"; fi >> - if [ "${encrypt}" = "enable" ]; then >> base_yaml="${base_yaml}:kas/opt/encrypt-data.yml"; fi >> - if [ "${factory_reset}" = "enable" ]; then >> base_yaml="${base_yaml}:kas/opt/factory-reset.yml"; fi >> @@ -399,6 +401,57 @@ build:qemu-arm-base-sid: >> separate_home_partition: enable >> deploy: enable >> >> +# forky image builds >> +.build_base_forky: >> + extends: >> + - .build_base >> + rules: >> + - if: $CI_COMMIT_TAG >> + when: never >> + - if: '$CI_PIPELINE_SOURCE == "schedule" && $CI_RUN_UNSTABLE' > > I meant we should migrate both forky and sid under this one > CI_RUN_UNSTABLE variable. Now we would still have two of them and would > need to set them both in the pipeline schedule. My idea was as below, - The CI variable CI_RUN_UNSTABLE_FORKY is changed to CI_RUN_UNSTABLE, however CI_RUN_UNSTABLE_SID is not changed in this patch series, will update in a separate patch as it is not related to this series. And it was mentioned in the v2 patch series cover letter, I think you would have missed that. let me know if required I will change CI_RUN_UNSTABLE_SID to CI_RUN_UNSTABLE in this series only. Thanks & Regards Shivanand K [-- Attachment #2: Type: text/html, Size: 3427 bytes --] ^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky 2026-07-29 4:26 ` Kunijadar Shivanand @ 2026-08-03 9:47 ` Kunijadar Shivanand 2026-08-10 14:45 ` Jan Kiszka 0 siblings, 1 reply; 8+ messages in thread From: Kunijadar Shivanand @ 2026-08-03 9:47 UTC (permalink / raw) To: cip-dev [-- Attachment #1: Type: text/plain, Size: 3293 bytes --] Hi Jan, On Tue, Jul 28, 2026 at 09:26 PM, Kunijadar Shivanand wrote: > > On Tue, Jul 28, 2026 at 08:29 AM, Jan Kiszka wrote: > >> On 28.07.26 10:55, Shivanand.Kunijadar@toshiba-tsip.com wrote: >> >>> From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> >>> >>> Keep these jobs as scheduled and can be scheduled to run every week >>> just to monitor and fix if there are any issues. >>> Also set allow_failure:true for these jobs as forky is not officially >>> released and there will always be some build & test issues. >>> >>> It includes SWUpdate, secure boot & RB tests. >>> >>> Signed-off-by: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> >>> --- >>> .gitlab-ci.yml | 148 +++++++++++++++++++++++++++++++++++++ >>> .reproducible-check-ci.yml | 72 ++++++++++++++++++ >>> 2 files changed, 220 insertions(+) >>> >>> diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml >>> index b53def4..b15c5da 100644 >>> --- a/.gitlab-ci.yml >>> +++ b/.gitlab-ci.yml >>> @@ -8,6 +8,7 @@ >>> # Jan Kiszka <jan.kiszka@siemens.com> >>> # Quirin Gylstorff <quirin.gylstorff@siemens.com> >>> # Nobuhiro Iwamatsu <nobuhiro1.iwamatsu@toshiba.co.jp> >>> +# Shivanand Kunijadar <shivanand.kunijadar@toshiba-tsip.com> >>> # >>> # SPDX-License-Identifier: MIT >>> # >>> @@ -63,6 +64,7 @@ default: >>> - if [ "${release}" = "bullseye" ]; then >>> base_yaml="${base_yaml}:kas/opt/bullseye.yml"; fi >>> - if [ "${release}" = "bookworm" ]; then >>> base_yaml="${base_yaml}:kas/opt/bookworm.yml"; fi >>> - if [ "${release}" = "trixie" ]; then >>> base_yaml="${base_yaml}:kas/opt/trixie.yml"; fi >>> + - if [ "${release}" = "forky" ]; then >>> base_yaml="${base_yaml}:kas/opt/forky.yml"; fi >>> - if [ "${release}" = "sid" ]; then >>> base_yaml="${base_yaml}:kas/opt/sid.yml"; fi >>> - if [ "${encrypt}" = "enable" ]; then >>> base_yaml="${base_yaml}:kas/opt/encrypt-data.yml"; fi >>> - if [ "${factory_reset}" = "enable" ]; then >>> base_yaml="${base_yaml}:kas/opt/factory-reset.yml"; fi >>> @@ -399,6 +401,57 @@ build:qemu-arm-base-sid: >>> separate_home_partition: enable >>> deploy: enable >>> >>> +# forky image builds >>> +.build_base_forky: >>> + extends: >>> + - .build_base >>> + rules: >>> + - if: $CI_COMMIT_TAG >>> + when: never >>> + - if: '$CI_PIPELINE_SOURCE == "schedule" && $CI_RUN_UNSTABLE' >> >> I meant we should migrate both forky and sid under this one >> CI_RUN_UNSTABLE variable. Now we would still have two of them and would >> need to set them both in the pipeline schedule. > > > My idea was as below, > > > - The CI variable CI_RUN_UNSTABLE_FORKY is changed to CI_RUN_UNSTABLE, > > > > however CI_RUN_UNSTABLE_SID is not changed in this patch series, will > > > > update in a separate patch as it is not related to this series. > > > > > > > > And it was mentioned in the v2 patch series cover letter, I think you > would have missed that. > > > > let me know if required I will change CI_RUN_UNSTABLE_SID to > CI_RUN_UNSTABLE in this series only. > > > > > > > Any comments on this? Shall i include the above change in this patch series? please let me know, will send v3 patch series accordingly. Thanks & Regards Shivanand K [-- Attachment #2: Type: text/html, Size: 3846 bytes --] ^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky 2026-08-03 9:47 ` Kunijadar Shivanand @ 2026-08-10 14:45 ` Jan Kiszka 2026-08-11 9:20 ` Kunijadar Shivanand 0 siblings, 1 reply; 8+ messages in thread From: Jan Kiszka @ 2026-08-10 14:45 UTC (permalink / raw) To: Kunijadar Shivanand, cip-dev On 03.08.26 11:47, Kunijadar Shivanand wrote: > Hi Jan, > > On Tue, Jul 28, 2026 at 09:26 PM, Kunijadar Shivanand wrote: > > On Tue, Jul 28, 2026 at 08:29 AM, Jan Kiszka wrote: > > On 28.07.26 10:55, Shivanand.Kunijadar@toshiba-tsip.com wrote: > > From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> > > Keep these jobs as scheduled and can be scheduled to run > every week > just to monitor and fix if there are any issues. > Also set allow_failure:true for these jobs as forky is not > officially > released and there will always be some build & test issues. > > It includes SWUpdate, secure boot & RB tests. > > Signed-off-by: Shivanand Kunijadar > <Shivanand.Kunijadar@toshiba-tsip.com> > --- > .gitlab-ci.yml | 148 +++++++++++++++++++++++++++++++++++++ > .reproducible-check-ci.yml | 72 ++++++++++++++++++ > 2 files changed, 220 insertions(+) > > diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml > index b53def4..b15c5da 100644 > --- a/.gitlab-ci.yml > +++ b/.gitlab-ci.yml > @@ -8,6 +8,7 @@ > # Jan Kiszka <jan.kiszka@siemens.com> > # Quirin Gylstorff <quirin.gylstorff@siemens.com> > # Nobuhiro Iwamatsu <nobuhiro1.iwamatsu@toshiba.co.jp> > +# Shivanand Kunijadar <shivanand.kunijadar@toshiba-tsip.com> > # > # SPDX-License-Identifier: MIT > # > @@ -63,6 +64,7 @@ default: > - if [ "${release}" = "bullseye" ]; then > base_yaml="${base_yaml}:kas/opt/bullseye.yml"; fi > - if [ "${release}" = "bookworm" ]; then > base_yaml="${base_yaml}:kas/opt/bookworm.yml"; fi > - if [ "${release}" = "trixie" ]; then > base_yaml="${base_yaml}:kas/opt/trixie.yml"; fi > + - if [ "${release}" = "forky" ]; then > base_yaml="${base_yaml}:kas/opt/forky.yml"; fi > - if [ "${release}" = "sid" ]; then > base_yaml="${base_yaml}:kas/opt/sid.yml"; fi > - if [ "${encrypt}" = "enable" ]; then > base_yaml="${base_yaml}:kas/opt/encrypt-data.yml"; fi > - if [ "${factory_reset}" = "enable" ]; then > base_yaml="${base_yaml}:kas/opt/factory-reset.yml"; fi > @@ -399,6 +401,57 @@ build:qemu-arm-base-sid: > separate_home_partition: enable > deploy: enable > > +# forky image builds > +.build_base_forky: > + extends: > + - .build_base > + rules: > + - if: $CI_COMMIT_TAG > + when: never > + - if: '$CI_PIPELINE_SOURCE == "schedule" && $CI_RUN_UNSTABLE' > > I meant we should migrate both forky and sid under this one > CI_RUN_UNSTABLE variable. Now we would still have two of them > and would > need to set them both in the pipeline schedule. > > My idea was as below, > > - The CI variable CI_RUN_UNSTABLE_FORKY is changed to CI_RUN_UNSTABLE, > > however CI_RUN_UNSTABLE_SID is not changed in this patch series, will > > update in a separate patch as it is not related to this series. > > > > And it was mentioned in the v2 patch series cover letter, I think > you would have missed that. > > let me know if required I will change CI_RUN_UNSTABLE_SID to > CI_RUN_UNSTABLE in this series only. > > > > Any comments on this? Shall i include the above change in this patch > series? > > please let me know, will send v3 patch series accordingly. > Please rename CI_RUN_UNSTABLE_SID to CI_RUN_UNSTABLE before introducing forky as another user. Will easy to pipeline maintenance. Jan -- Siemens AG, Foundational Technologies Linux Expert Center ^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky 2026-08-10 14:45 ` Jan Kiszka @ 2026-08-11 9:20 ` Kunijadar Shivanand 0 siblings, 0 replies; 8+ messages in thread From: Kunijadar Shivanand @ 2026-08-11 9:20 UTC (permalink / raw) To: cip-dev [-- Attachment #1: Type: text/plain, Size: 3547 bytes --] Hi Jan, On Mon, Aug 10, 2026 at 07:46 AM, Jan Kiszka wrote: > > On 03.08.26 11:47, Kunijadar Shivanand wrote: > >> Hi Jan, >> >> On Tue, Jul 28, 2026 at 09:26 PM, Kunijadar Shivanand wrote: >> >> On Tue, Jul 28, 2026 at 08:29 AM, Jan Kiszka wrote: >> >> On 28.07.26 10:55, Shivanand.Kunijadar@toshiba-tsip.com wrote: >> >> From: Shivanand Kunijadar <Shivanand.Kunijadar@toshiba-tsip.com> >> >> Keep these jobs as scheduled and can be scheduled to run >> every week >> just to monitor and fix if there are any issues. >> Also set allow_failure:true for these jobs as forky is not >> officially >> released and there will always be some build & test issues. >> >> It includes SWUpdate, secure boot & RB tests. >> >> Signed-off-by: Shivanand Kunijadar >> <Shivanand.Kunijadar@toshiba-tsip.com> >> --- >> .gitlab-ci.yml | 148 +++++++++++++++++++++++++++++++++++++ >> .reproducible-check-ci.yml | 72 ++++++++++++++++++ >> 2 files changed, 220 insertions(+) >> >> diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml >> index b53def4..b15c5da 100644 >> --- a/.gitlab-ci.yml >> +++ b/.gitlab-ci.yml >> @@ -8,6 +8,7 @@ >> # Jan Kiszka <jan.kiszka@siemens.com> >> # Quirin Gylstorff <quirin.gylstorff@siemens.com> >> # Nobuhiro Iwamatsu <nobuhiro1.iwamatsu@toshiba.co.jp> >> +# Shivanand Kunijadar <shivanand.kunijadar@toshiba-tsip.com> >> # >> # SPDX-License-Identifier: MIT >> # >> @@ -63,6 +64,7 @@ default: >> - if [ "${release}" = "bullseye" ]; then >> base_yaml="${base_yaml}:kas/opt/bullseye.yml"; fi >> - if [ "${release}" = "bookworm" ]; then >> base_yaml="${base_yaml}:kas/opt/bookworm.yml"; fi >> - if [ "${release}" = "trixie" ]; then >> base_yaml="${base_yaml}:kas/opt/trixie.yml"; fi >> + - if [ "${release}" = "forky" ]; then >> base_yaml="${base_yaml}:kas/opt/forky.yml"; fi >> - if [ "${release}" = "sid" ]; then >> base_yaml="${base_yaml}:kas/opt/sid.yml"; fi >> - if [ "${encrypt}" = "enable" ]; then >> base_yaml="${base_yaml}:kas/opt/encrypt-data.yml"; fi >> - if [ "${factory_reset}" = "enable" ]; then >> base_yaml="${base_yaml}:kas/opt/factory-reset.yml"; fi >> @@ -399,6 +401,57 @@ build:qemu-arm-base-sid: >> separate_home_partition: enable >> deploy: enable >> >> +# forky image builds >> +.build_base_forky: >> + extends: >> + - .build_base >> + rules: >> + - if: $CI_COMMIT_TAG >> + when: never >> + - if: '$CI_PIPELINE_SOURCE == "schedule" && $CI_RUN_UNSTABLE' >> >> I meant we should migrate both forky and sid under this one >> CI_RUN_UNSTABLE variable. Now we would still have two of them >> and would >> need to set them both in the pipeline schedule. >> >> My idea was as below, >> >> - The CI variable CI_RUN_UNSTABLE_FORKY is changed to CI_RUN_UNSTABLE, >> >> however CI_RUN_UNSTABLE_SID is not changed in this patch series, will >> >> update in a separate patch as it is not related to this series. >> >> >> >> And it was mentioned in the v2 patch series cover letter, I think >> you would have missed that. >> >> let me know if required I will change CI_RUN_UNSTABLE_SID to >> CI_RUN_UNSTABLE in this series only. >> >> >> >> Any comments on this? Shall i include the above change in this patch >> series? >> >> please let me know, will send v3 patch series accordingly. > > Please rename CI_RUN_UNSTABLE_SID to CI_RUN_UNSTABLE before introducing > forky as another user. Will easy to pipeline maintenance. Thanks, fixed in v3 patch series. please check it. Thanks & Regards Shivanand K [-- Attachment #2: Type: text/html, Size: 3906 bytes --] ^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-08-11 9:21 UTC | newest] Thread overview: 8+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-07-28 8:55 [isar-cip-core][PATCH v2 0/2] Enable debian forky build & test support Shivanand.Kunijadar 2026-07-28 8:55 ` [isar-cip-core][PATCH v2 1/2] Enable the support of Debian forky based builds Shivanand.Kunijadar 2026-07-28 8:55 ` [isar-cip-core][PATCH v2 2/2] Enable CI image build and test support for forky Shivanand.Kunijadar 2026-07-28 15:29 ` Jan Kiszka 2026-07-29 4:26 ` Kunijadar Shivanand 2026-08-03 9:47 ` Kunijadar Shivanand 2026-08-10 14:45 ` Jan Kiszka 2026-08-11 9:20 ` Kunijadar Shivanand
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox