diff --git a/.github/workflows/iso-2-gitea-build.yml b/.github/workflows/iso-2-gitea-build.yml index f503c2a..f91e15a 100644 --- a/.github/workflows/iso-2-gitea-build.yml +++ b/.github/workflows/iso-2-gitea-build.yml @@ -4,11 +4,11 @@ # checksums and package list to the mirror's release for that tag. The tag names the Steamify version and # the time: v-- (master) or v-dev.<...> (feat/steamify, a pre-release); # the ISO gets exactly that Steamify release, and its label the same moment. GitHub skips it. -# Three jobs: build the ISO -> test that it installs correctly (vmbootloadertest.sh --quick of steamify-cachyos-dev per loader, in -# parallel when the runner's capacity allows) -> release, only when every test passed. (The suites that test steamify.sh run in steamify-cachyos, vmtest.yml.) -# The runner needs /dev/kvm, privileged containers (archiso mounts loop devices) and ~20 GB of disk; Gitea's +# Two jobs: build the ISO -> release it. The VM tests run on GitHub (steamify-cachyos vmtest.yml, the newest ISO release of +# this mirror), where the runners are bigger. +# The runner needs privileged containers (archiso mounts loop devices) and ~20 GB of disk; Gitea's # [repository.release] FILE_MAX_SIZE must allow the ISO (default 2 GB). -name: ISO 2/2 · Build, test and publish (Gitea) +name: ISO 2/2 · Build and publish (Gitea) on: push: @@ -95,143 +95,9 @@ jobs: out/desktop/*.pkgs.txt retention-days: 3 - test-fremont: - name: Steam Machine ${{ matrix.loader }} - needs: build - runs-on: ubuntu-latest - timeout-minutes: 90 - container: - image: docker.io/cachyos/cachyos:latest - options: --privileged - strategy: - fail-fast: false - # max-parallel is ignored by this runner (it starts all three), so the VMs are lean: 3 x 5 GB to install. - max-parallel: 2 - matrix: - loader: [limine, systemd-boot, grub] - defaults: - run: - shell: bash - # No `uses:` in this job on purpose: the three jobs start in the same second, and the runner clones every - # action into one shared folder (they broke each other's checkout of actions/cache). Plain git and curl instead. - steps: - - name: Tools and KVM - run: | - pacman-key --init && pacman-key --populate - pacman -Syu --noconfirm --needed qemu-desktop edk2-ovmf openssh libarchive procps-ng util-linux python git sudo curl unzip - # Fail at once, with a reason, when the runner cannot run a VM with KVM. - [ -c /dev/kvm ] || { echo "::error::no /dev/kvm in this container: the runner needs KVM (and privileged containers)"; exit 1; } - nproc; free -g | sed -n 2p; df -h . | tail -n 1 - - # The test scripts expect their repos side by side: steamify-cachyos-dev (the scripts), steamify-cachyos at - # the Steamify version the ISO has (shared into the VM, 9p `repo`), and the ISO this run built (its artifact). - - name: Scripts, Steamify and the ISO - run: | - base="${{ github.server_url }}" - git clone -q --depth 1 "$base/theupriser/steamify-cachyos-dev" steamify-cachyos-dev - git clone -q --depth 1 --branch "v${{ needs.build.outputs.steamify }}" "$base/theupriser/steamify-cachyos" steamify-cachyos - api="$base/api/v1/repos/${{ github.repository }}/actions" - id="$(curl -fsS "$api/runs/${{ github.run_id }}/artifacts" | python3 -c "import json,sys; print(next(a['id'] for a in json.load(sys.stdin)['artifacts'] if a['name']=='iso'))")" - curl -fsSL --retry 5 --retry-all-errors -o iso.zip "$api/artifacts/$id/zip" - unzip -q iso.zip -d iso && rm iso.zip - ls -la iso - - - name: Boot loader test, Steam Machine (${{ matrix.loader }}) - env: - CI: "1" - VM_TIMEZONE: UTC - # The runner is 4 cores / 8 threads: three VMs with 2 vCPUs leave 2 threads for the host and the runner. - VM_CPUS: "2" - # RAM of the live installer VM (the ISO is read from its cdrom, only the overlay and the installer use RAM). - VM_INSTALL_MEM: 5G - VM_ISO_DIR: ${{ github.workspace }}/iso - run: | - mkdir -p ~/.ssh ~/vms/pkg-cache - ssh-keygen -q -t ed25519 -N "" -C steamify-vm -f ~/.ssh/steamify-vm_ed25519 - iso="$(ls "$VM_ISO_DIR"/*.iso | head -n 1)" - cd steamify-cachyos-dev - VM_ISO="$iso" scripts/vmbootloadertest.sh "${{ matrix.loader }}" --install --quick - - # The logs go into this job's log (public), no artifact action needed. - - name: VM logs - if: always() - run: | - for f in ~/vms/bl-${{ matrix.loader }}/install.log ~/vms/bl-${{ matrix.loader }}/serial.log ~/vms/bl-${{ matrix.loader }}/vm.log; do - [ -s "$f" ] && { echo "::group::$f (last 150 lines)"; tail -n 150 "$f" | sed 's/\x1b\[[0-9;]*m//g'; echo "::endgroup::"; } - done - true - - test-generic: - name: Plain PC ${{ matrix.loader }} - # After the Steam Machine tests (RAM: 3 VMs at a time), also when one of those failed. - needs: [build, test-fremont] - if: ${{ !cancelled() && needs.build.result == 'success' }} - runs-on: ubuntu-latest - timeout-minutes: 90 - container: - image: docker.io/cachyos/cachyos:latest - options: --privileged - strategy: - fail-fast: false - # max-parallel is ignored by this runner (it starts all three), so the VMs are lean: 3 x 5 GB to install. - max-parallel: 2 - matrix: - loader: [limine, systemd-boot, grub] - defaults: - run: - shell: bash - # No `uses:` in this job on purpose: the three jobs start in the same second, and the runner clones every - # action into one shared folder (they broke each other's checkout of actions/cache). Plain git and curl instead. - steps: - - name: Tools and KVM - run: | - pacman-key --init && pacman-key --populate - pacman -Syu --noconfirm --needed qemu-desktop edk2-ovmf openssh libarchive procps-ng util-linux python git sudo curl unzip - # Fail at once, with a reason, when the runner cannot run a VM with KVM. - [ -c /dev/kvm ] || { echo "::error::no /dev/kvm in this container: the runner needs KVM (and privileged containers)"; exit 1; } - nproc; free -g | sed -n 2p; df -h . | tail -n 1 - - # The test scripts expect their repos side by side: steamify-cachyos-dev (the scripts), steamify-cachyos at - # the Steamify version the ISO has (shared into the VM, 9p `repo`), and the ISO this run built (its artifact). - - name: Scripts, Steamify and the ISO - run: | - base="${{ github.server_url }}" - git clone -q --depth 1 "$base/theupriser/steamify-cachyos-dev" steamify-cachyos-dev - git clone -q --depth 1 --branch "v${{ needs.build.outputs.steamify }}" "$base/theupriser/steamify-cachyos" steamify-cachyos - api="$base/api/v1/repos/${{ github.repository }}/actions" - id="$(curl -fsS "$api/runs/${{ github.run_id }}/artifacts" | python3 -c "import json,sys; print(next(a['id'] for a in json.load(sys.stdin)['artifacts'] if a['name']=='iso'))")" - curl -fsSL --retry 5 --retry-all-errors -o iso.zip "$api/artifacts/$id/zip" - unzip -q iso.zip -d iso && rm iso.zip - ls -la iso - - - name: Boot loader test, plain PC (${{ matrix.loader }}) - env: - CI: "1" - VM_TIMEZONE: UTC - # The runner is 4 cores / 8 threads: three VMs with 2 vCPUs leave 2 threads for the host and the runner. - VM_CPUS: "2" - # RAM of the live installer VM (the ISO is read from its cdrom, only the overlay and the installer use RAM). - VM_INSTALL_MEM: 5G - VM_ISO_DIR: ${{ github.workspace }}/iso - run: | - mkdir -p ~/.ssh ~/vms/pkg-cache - ssh-keygen -q -t ed25519 -N "" -C steamify-vm -f ~/.ssh/steamify-vm_ed25519 - iso="$(ls "$VM_ISO_DIR"/*.iso | head -n 1)" - cd steamify-cachyos-dev - VM_ISO="$iso" scripts/vmbootloadertest.sh "${{ matrix.loader }}" --install --quick --generic - - # The logs go into this job's log (public), no artifact action needed. - - name: VM logs - if: always() - run: | - for f in ~/vms/bl-${{ matrix.loader }}-generic/install.log ~/vms/bl-${{ matrix.loader }}-generic/serial.log ~/vms/bl-${{ matrix.loader }}-generic/vm.log; do - [ -s "$f" ] && { echo "::group::$f (last 150 lines)"; tail -n 150 "$f" | sed 's/\x1b\[[0-9;]*m//g'; echo "::endgroup::"; } - done - true - release: name: Release - needs: [build, test-fremont, test-generic] + needs: build runs-on: ubuntu-latest container: image: docker.io/cachyos/cachyos:latest diff --git a/AGENTS.md b/AGENTS.md index afa2f0e..3f11d4c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -118,10 +118,9 @@ Full write-up, with every trap: `steamify-iso-release` in steamify-cachyos-dev. release, whose `bundle.yml` needs the secret `ISO_DISPATCH_TOKEN`) names the release: the Steamify version plus GitHub's UTC time, `vX.Y.Z-[dev.]YYYY.MM.DD-HHMM`, an **annotated** tag and a release with notes and the direct download link. `feat/steamify` makes a `dev.` pre-release, `master` a real one. -- `.github/workflows/iso-2-gitea-build.yml` (Gitea, `on: push: tags: v*`, skipped on GitHub) runs three jobs for that - tag: build the ISO, test it (steamify-cachyos-dev's `scripts/vmbootloadertest.sh --install --quick` (only that the ISO installs correctly: boot entry, OS name, loader, Steamify state and modules; steamify.sh itself is tested in steamify-cachyos) per loader on a VM that reports Steam Machine hardware (`--fremont`: poweroff, cec and the 3 DKMS modules must be there), then the same with `--generic` on a plain PC (they must not), - parallel up to the runner's capacity; needs `/dev/kvm` on the runner and checks out steamify-cachyos-dev `main` and - steamify-cachyos at the ISO's version from the mirror), and only when all tests passed attach it to the mirror's release. The tag decides everything: Steamify version (`steamify-prepare.sh` +- `.github/workflows/iso-2-gitea-build.yml` (Gitea, `on: push: tags: v*`, skipped on GitHub) runs two jobs for that + tag: build the ISO, then attach it to the mirror's release. It is not tested there (the runner is small): the VM tests + run on GitHub, in steamify-cachyos `vmtest.yml`, on the newest ISO release of the mirror. The tag decides everything: Steamify version (`steamify-prepare.sh` takes `STEAMIFY_VERSION`), file name (`STEAMIFY_ISO_VERSION` -> `iso_version` in `profiledef.sh`), label (`STEAMIFY_BUILD_STAMP`), boot menu and `/etc/steammachine-iso-build`. The build reads no clock; without a tag everything says `local`. @@ -132,4 +131,4 @@ Full write-up, with every trap: `steamify-iso-release` in steamify-cachyos-dev. - Gitea needs `[repository.release] FILE_MAX_SIZE` above the ISO (413 otherwise) and the runner `container: privileged: true` (archiso mounts `/proc`); the workflow's `--privileged` option is ignored. - Caches (`actions/cache`, the runner's cache server): pacman's package cache per job kind (build, test) and the VMs' packages (`VM_CACHE`, `~/vms/pkg-cache`), keys per ISO week. Each job first installs only node and git, restores the caches, then installs the rest. -- CachyOS's own `Desktop ISO` workflow (`build.yml`) is removed here; the test job of iso-2-gitea-build.yml replaces it. +- CachyOS's own `Desktop ISO` workflow (`build.yml`) is removed here; the VM tests live in steamify-cachyos (GitHub).