This GitHub workflow repo cross-compiles the Linux kernel (6.1.x) for ARM64 and distributes the output via GitHub Releases. The single-board computer (SBC) acts as an autonomous client; it verifies data integrity and installs the update locally.
- Production & Validation (GitHub Actions): Triggered by a cron schedule. The system fetches the official source code, verifies signatures against the
kernel.orgGit keyring, and cross-compiles deterministically usingccache. Unnecessary or hazardous packages (likelibc-devand debug binaries) are explicitly eliminated. - Cryptographic Lock (GitHub Actions): The remaining binaries (Image, Headers) are atomically hashed (
sha256sums.txt). - Immutable Storage (GitHub Releases): The binaries and the hash file are published as a Release in this private repository.
- Retrieval & Verification (SBC): A local root cron job on the target board queries the GitHub API using a read-only token. If a new release is detected, the files are downloaded and the mathematical hash is validated before any system modifications occur.
- Atomic Installation & Alerting (SBC): The packages are installed directly via
dpkg -i. The operating system reboot flag (/var/run/reboot-required) is set, and an asynchronous alert is sent to the administrator vias-nail.
| Environment | Dependency / Key | Function and Location |
|---|---|---|
| GitHub Repo | GITHUB_TOKEN |
Built into GHA. Requires permissions: contents: write in YAML to create Releases. No other secrets are used. |
| SBC (Client) | Fine-grained PAT | Read-only token scoped strictly to "Contents: Read" for this specific repository. Stored locally at /root/.github_token (chmod 400). |
| SBC (Client) | s-nail configuration |
Mail Transfer Agent for notifications via /etc/s-nail.rc, linked to an external SMTP relay (port 587/465). |
| SBC (Client) | jq |
JSON parser installed (apt install jq) for deterministic evaluation of GitHub API responses. |
The repository is governed exclusively by one configuration file. To modify the kernel's behavior:
- Modify settings locally:
make ARCH=arm64 menuconfig. - Save a minimal delta configuration:
make ARCH=arm64 savedefconfig. - Replace the file
kernel-configs/config-6.1-arm64with your generateddefconfig. - Commit the file. Cron and GitHub Actions will build all future kernels using these exact parameters.
When the system fails, use this matrix to identify the root cause:
| Failure Symptom | Causal Origin | Corrective Action |
|---|---|---|
| GHA: "Can't check signature" | New PGP keys were added upstream without updating pgpkeys.git, or there is an issue with the kernel.org Git repository. |
Check GHA logs. If it is a transient Git failure, wait for the next scheduled cron job. |
| SBC: No update occurs | The token (.github_token) has expired or been deleted. |
Check the local log (cat /var/log/update-kernel.log). Generate a new PAT in GitHub and update /root/.github_token. |
| SBC: Installation crashes | Disk space on /boot (FAT32/ext4) is exhausted. |
The local script enforces a margin of safety (>50MB requirement). Manually purge old, unused kernels if this warning triggers. |
| SBC: No email alerts | The SMTP password in /etc/s-nail.rc was changed, or the provider is blocking the port. |
Run echo "test" | s-nail -s "Test" your@email.com -v to diagnose the SMTP network error. |