Skip to content

About

Github Actions for kernel

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

9 Commits

Folders and files

Repository files navigation

System Architecture: Automated Kernel Compilation (Linux 6.1 ARM64)

System Description

This GitHub workflow repo cross-compiles the Linux kernel (6.1.x) for ARM64 and distributes the output via GitHub Releases. The single-board computer (SBC) acts as an autonomous client; it verifies data integrity and installs the update locally.

Architecture and Data Flow (Direct Pull Model)

  1. Production & Validation (GitHub Actions): Triggered by a cron schedule. The system fetches the official source code, verifies signatures against the kernel.org Git keyring, and cross-compiles deterministically using ccache. Unnecessary or hazardous packages (like libc-dev and debug binaries) are explicitly eliminated.
  2. Cryptographic Lock (GitHub Actions): The remaining binaries (Image, Headers) are atomically hashed (sha256sums.txt).
  3. Immutable Storage (GitHub Releases): The binaries and the hash file are published as a Release in this private repository.
  4. Retrieval & Verification (SBC): A local root cron job on the target board queries the GitHub API using a read-only token. If a new release is detected, the files are downloaded and the mathematical hash is validated before any system modifications occur.
  5. Atomic Installation & Alerting (SBC): The packages are installed directly via dpkg -i. The operating system reboot flag (/var/run/reboot-required) is set, and an asynchronous alert is sent to the administrator via s-nail.

Operational Dependencies (State & Secrets)

Environment Dependency / Key Function and Location
GitHub Repo GITHUB_TOKEN Built into GHA. Requires permissions: contents: write in YAML to create Releases. No other secrets are used.
SBC (Client) Fine-grained PAT Read-only token scoped strictly to "Contents: Read" for this specific repository. Stored locally at /root/.github_token (chmod 400).
SBC (Client) s-nail configuration Mail Transfer Agent for notifications via /etc/s-nail.rc, linked to an external SMTP relay (port 587/465).
SBC (Client) jq JSON parser installed (apt install jq) for deterministic evaluation of GitHub API responses.

Configuration Management (Single Source of Truth)

The repository is governed exclusively by one configuration file. To modify the kernel's behavior:

  1. Modify settings locally: make ARCH=arm64 menuconfig.
  2. Save a minimal delta configuration: make ARCH=arm64 savedefconfig.
  3. Replace the file kernel-configs/config-6.1-arm64 with your generated defconfig.
  4. Commit the file. Cron and GitHub Actions will build all future kernels using these exact parameters.

Recovery and Diagnostics (Inversion)

When the system fails, use this matrix to identify the root cause:

Failure Symptom Causal Origin Corrective Action
GHA: "Can't check signature" New PGP keys were added upstream without updating pgpkeys.git, or there is an issue with the kernel.org Git repository. Check GHA logs. If it is a transient Git failure, wait for the next scheduled cron job.
SBC: No update occurs The token (.github_token) has expired or been deleted. Check the local log (cat /var/log/update-kernel.log). Generate a new PAT in GitHub and update /root/.github_token.
SBC: Installation crashes Disk space on /boot (FAT32/ext4) is exhausted. The local script enforces a margin of safety (>50MB requirement). Manually purge old, unused kernels if this warning triggers.
SBC: No email alerts The SMTP password in /etc/s-nail.rc was changed, or the provider is blocking the port. Run echo "test" | s-nail -s "Test" your@email.com -v to diagnose the SMTP network error.

About

Github Actions for kernel

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages