Repository navigation
ci: build native release artifacts inside the canonical dev container and verify container-build provenance (ADR-1178) - #1305
Merged
Conversation
lusoris
force-pushed
the
ci/release-artifacts-built-in-dev-container
branch
4 times, most recently
from
September 6, 2026 02:59
9ce1828 to
774b100
Compare
…tainer enforcement (ADR-1178)
…nd record the runner-disk blocker (ADR-1178) The build-artifacts job pinned ghcr.io/vmafx/vmafx-dev-mcp to sha256:ff297e6d…, which is the local image ID of the workstation's vmaf-dev-mcp:local build, not a GHCR manifest digest; nothing is published under that name yet, so every release run would have failed at container pull. Reference the :master tag instead and let the renovate.json pinDigests rule pin :master@sha256:<digest> after the first dev-container-publish.yml run. Replace the research digest's estimated image sizes with measured layer sums (libvmaf-build ≈ 29.5 GB uncompressed) and record that the standard GitHub-hosted public-repo runner lists 14 GB of SSD, which a job-level container: pull cannot be trimmed around; the ADR's Consequences now carry that as an unresolved blocker with option (c) as the fallback. Also removes a stray blank line that split the docs/state.md Recently-closed table.
…l runner (ADR-1178) Rework build-artifacts in supply-chain.yml to run on the Arc A380 containerised self-hosted runner ([self-hosted, linux, x64, sycl-arc], provisioned by ADR-1177 / PR #1304) using the local canonical dev container environment (vmaf-sycl-arc-runner:local, built FROM vmaf-dev-mcp:local) without registry pull. Update check-container-build.sh detector to accept canonical runner image title, configure actionlint runner labels, and update ADR-1178, research digest, and publishing docs.
…rebase note (ADR-1178)
Each dropped row restates one origin/master already carries; master is the authoritative record. Verified with scripts/ci/check-state-md-rows.sh. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
lusoris
force-pushed
the
ci/release-artifacts-built-in-dev-container
branch
from
September 6, 2026 06:39
774b100 to
020284d
Compare
lusoris
marked this pull request as ready for review
September 6, 2026 08:10
42 tasks
2 of 7 tasks
lusoris
added a commit
that referenced
this pull request
Oct 1, 2026
…23e8f2 (#1761) * docs: record the fork's check of the upstream defects verified on 6ec23e8f2 Fifteen defects reproduced on Netflix master were run against the fork: three reproduced and are fixed (#1305, #1420 as a hang, #1613), two are documented (#910, #755 and #1180), ten are not affected. The dated section in known-upstream-bugs.md and the Confirmed not-affected rows of the state ledger carry the evidence; Netflix 8e7a1ac4e (revert of #1476) needs nothing from the fork. * docs: regenerate the indexes and the citation map after rebasing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Reworks native release artifact compilation (
build-artifactsin.github/workflows/supply-chain.yml) to execute on the Intel Arc A380 containerised self-hosted runner (labels:[self-hosted, linux, x64, sycl-arc], provisioned by ADR-1177 / PR #1304) using the workstation's local canonical dev container environment (vmaf-sycl-arc-runner:local, derivedFROM vmaf-dev-mcp:local) without any registry pull per ADR-1178 (Phase 4b.9). This completely bypasses the 29.5 GB uncompressed layer pull blocker on standard GitHub-hostedubuntu-latestrunners (14 GB SSD limit). The runner container itself is the build environment (contains GCC-13/15, Clang-19, Meson, Ninja, Python 3.14, oneAPI, CUDA 13.3, ROCm 7.2.4, and/etc/vmafx-dev-container; no Docker socket needed). Protected by a canonical tag-release guard (github.repository == 'VMAFx/vmafx' && startsWith(github.ref, 'refs/tags/v')), serialized concurrency (concurrency: group: release-artifacts-build), and generoustimeout-minutes: 90. Staged release artifacts are stamped with container-build provenance viascripts/ci/check-container-build.sh --stamp, which now accepts bothvmaf-dev-mcpandvmaf-sycl-arc-runnerwhile strictly rejecting bareubuntu-latest(exit 1). Downstreamverify-native-artifactsonubuntu-latestruns--verify,scripts/release/verify-native-release-artifacts.shfails closed if the stamp is missing/empty/symlinked, andattach-to-releaserequires the provenance file alongside Cosign signatures..github/workflows/dev-container-publish.ymlis retained as optional provenance on GHCR, decoupled from release artifact compilation. Configures.github/actionlint.yamlwith custom self-hosted labels.Verification:
actionlinton both workflows exit 0;scripts/ci/tests/test-check-container-build.sh31 passed, 0 failed;scripts/release/tests/test-verify-native-release-artifacts.sh10 passed, 0 failed;scripts/release/tests/test-publication-environment-binding.shall PASS; pre-commit on every touched file all hooks passed;concat-changelog-fragments.sh --checkexit 0;concat-adr-index.sh --checkexit 0.Type
ci— build native release artifacts on self-hosted Arc A380 canonical runner (ADR-1178)Checklist
make format && make lintis green locally (pre-commit on every touched file).bash scripts/ci/tests/test-check-container-build.sh(31 passed),bash scripts/release/tests/test-verify-native-release-artifacts.sh(10 passed),bash scripts/release/tests/test-publication-environment-binding.sh(all PASS),actionlinton both workflows (exit 0).docs/development/publishing.md,docs/development/release.md,docs/adr/1178-dev-container-image-publish.md,docs/research/1178-dev-container-image-publish.md.docs/adr/1178-dev-container-image-publish.md(+ index fragment,_order.txt, regenerateddocs/adr/README.md).Bug-status hygiene (ADR-0165)
docs/state.md—T-PUBLISH-NATIVE-RELEASE-NOT-CONTAINERISED-2026-09-03moved from Open to Recently closed (branchci/release-artifacts-built-in-dev-container).Netflix golden-data gate (ADR-0024)
assertAlmostEqual(...)score in the Netflix golden Python tests.Deep-dive deliverables (ADR-0108)
docs/research/1178-dev-container-image-publish.mddocs/adr/1178-dev-container-image-publish.md(Alternatives: (a) self-hosted Arc A380 runner with local image [chosen], (b) GHCR dev container pull [lost to 29.5GB blocker], (c) slim release-only stage, (d) on-the-fly build)AGENTS.mdinvariant note — no rebase-sensitive invariants: fork-only CI workflows and release scripts, nothing upstream Netflix/vmaf touches.changelog.d/changed/release-artifacts-built-in-dev-container.mddocs/rebase-notes.mdentry (ci/release-artifacts-built-in-dev-container, no rebase impact: fork-only CI)Reproducer