Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/kernel.yml
Original file line number Diff line number Diff line change
Expand Up @@ -68,4 +68,4 @@ jobs:
run: |
tag=$(go run ./packaging/kernel/tag)
cat dist/*.sha256 > dist/SHA256SUMS
gh release create "$tag" --target "$GITHUB_SHA" --title "guest kernel $tag" --latest=false --notes "Built by the kernel workflow from packaging/kernel. Reproducible: each file was built twice." dist/Image-arm64 dist/vmlinux-amd64 dist/SHA256SUMS
gh release create "$tag" --target "$GITHUB_SHA" --title "guest-$tag" --latest=false --notes "Built by the kernel workflow from packaging/kernel. Reproducible: each file was built twice." dist/Image-arm64 dist/vmlinux-amd64 dist/SHA256SUMS
5 changes: 3 additions & 2 deletions docs/kernel.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,8 +43,9 @@ with Docker builds it faster.
The `kernel` workflow (`.github/workflows/kernel.yml`) runs on manual dispatch only. It builds each
arch twice and compares the hashes. It checks them against the hashes that `services/kernel` was
built with, then publishes `Image-arm64`, `vmlinux-amd64` and `SHA256SUMS` under the release tag
`kernel-<version>-<build>`. A hash that does not match what the Go code expects fails the workflow,
so a release can never carry a kernel that the daemon would refuse.
`kernel-<version>-<build>`, titled `guest-kernel-<version>-<build>`. A hash that does not match what
the Go code expects fails the workflow, so a release can never carry a kernel that the daemon would
refuse.

When the daemon creates a microVM provider, it checks the kernel file for the host arch. On first
use, it fetches the file into `<root>/kernel/<tag>/` and fsyncs the file and its directory. At this
Expand Down
Loading