diff --git a/.github/workflows/audit.yaml b/.github/workflows/audit.yaml deleted file mode 100644 index bab8eaa14..000000000 --- a/.github/workflows/audit.yaml +++ /dev/null @@ -1,16 +0,0 @@ -name: Cloud Hypervisor Dependency Audit -on: - pull_request: - paths: - - '**/Cargo.toml' - - '**/Cargo.lock' - -jobs: - security_audit: - name: Audit - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - - uses: actions-rust-lang/audit@v1 - with: - token: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml deleted file mode 100644 index 628c163db..000000000 --- a/.github/workflows/build.yaml +++ /dev/null @@ -1,80 +0,0 @@ -name: Cloud Hypervisor Build -on: [pull_request, merge_group] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Build - runs-on: ubuntu-latest - strategy: - fail-fast: false - matrix: - rust: - - stable - - beta - - nightly - - "1.89.0" - target: - - x86_64-unknown-linux-gnu - - x86_64-unknown-linux-musl - steps: - - name: Code checkout - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - - name: Install musl-gcc - run: sudo apt install -y musl-tools - - - name: Install Rust toolchain (${{ matrix.rust }}) - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - - - name: Build (default features) - run: cargo build --locked --bin cloud-hypervisor - - - name: Build (kvm) - run: cargo build --locked --bin cloud-hypervisor --no-default-features --features "kvm" - - - name: Build (default features + tdx) - run: cargo build --locked --bin cloud-hypervisor --features "tdx" - - - name: Build (default features + dbus_api) - run: cargo build --locked --bin cloud-hypervisor --features "dbus_api" - - - name: Build (default features + guest_debug) - run: cargo build --locked --bin cloud-hypervisor --features "guest_debug" - - - name: Build (default features + pvmemcontrol) - run: cargo build --locked --bin cloud-hypervisor --features "pvmemcontrol" - - - name: Build (default features + fw_cfg) - run: cargo build --locked --bin cloud-hypervisor --features "fw_cfg" - - - name: Build (default features + ivshmem) - run: cargo build --locked --bin cloud-hypervisor --features "ivshmem" - - - name: Build (mshv) - run: cargo build --locked --bin cloud-hypervisor --no-default-features --features "mshv" - - - name: Build (sev_snp) - run: cargo build --locked --bin cloud-hypervisor --no-default-features --features "sev_snp" - - - name: Build (kvm + igvm + sev_snp + fw_cfg) - run: cargo build --locked --bin cloud-hypervisor --no-default-features --features "kvm,igvm,sev_snp,fw_cfg" - - - name: Build (igvm) - run: cargo build --locked --bin cloud-hypervisor --no-default-features --features "igvm" - - - name: Build (mshv + kvm) - run: cargo build --locked --bin cloud-hypervisor --no-default-features --features "mshv,kvm" - - - name: Release Build (default features) - run: cargo build --locked --all --release --target=${{ matrix.target }} - - - name: Check build did not modify any files - run: test -z "$(git status --porcelain)" diff --git a/.github/workflows/dco.yaml b/.github/workflows/dco.yaml deleted file mode 100644 index 67dfadd5c..000000000 --- a/.github/workflows/dco.yaml +++ /dev/null @@ -1,21 +0,0 @@ -name: DCO -on: [pull_request, merge_group] - -jobs: - check: - name: DCO Check ("Signed-off-by") - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - - name: Set up Python 3.x - uses: actions/setup-python@v6 - with: - python-version: '3.x' - - name: Check DCO - if: ${{ github.event_name == 'pull_request' }} - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - set -eufo pipefail - pip3 install -U dco-check - dco-check -e "49699333+dependabot[bot]@users.noreply.github.com" diff --git a/.github/workflows/formatting.yaml b/.github/workflows/formatting.yaml deleted file mode 100644 index 8dee21e6b..000000000 --- a/.github/workflows/formatting.yaml +++ /dev/null @@ -1,32 +0,0 @@ -name: Cloud Hypervisor Code Formatting -on: [pull_request, merge_group] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Code Formatting - runs-on: ubuntu-latest - strategy: - matrix: - rust: - - nightly - target: - - x86_64-unknown-linux-gnu - - aarch64-unknown-linux-musl - env: - RUSTFLAGS: -D warnings - steps: - - name: Code checkout - uses: actions/checkout@v6 - - name: Install Rust toolchain (${{ matrix.rust }}) - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - components: rustfmt - - name: Formatting (rustfmt) - run: cargo fmt --all -- --check - - name: Formatting (fuzz) (rustfmt) - run: cargo fmt --all --manifest-path fuzz/Cargo.toml -- --check diff --git a/.github/workflows/fuzz-build.yaml b/.github/workflows/fuzz-build.yaml deleted file mode 100644 index d5f0332a9..000000000 --- a/.github/workflows/fuzz-build.yaml +++ /dev/null @@ -1,32 +0,0 @@ -name: Cloud Hypervisor Cargo Fuzz Build -on: [pull_request, merge_group] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Cargo Fuzz Build - runs-on: ubuntu-latest - strategy: - matrix: - rust: - - nightly - target: - - x86_64-unknown-linux-gnu - env: - RUSTFLAGS: -D warnings - steps: - - name: Code checkout - uses: actions/checkout@v6 - - name: Install Rust toolchain (${{ matrix.rust }}) - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - - name: Install Cargo fuzz - run: cargo install cargo-fuzz - - name: Fuzz Build - run: cargo fuzz build - - name: Fuzz Check - run: cargo fuzz check diff --git a/.github/workflows/gitlint.yaml b/.github/workflows/gitlint.yaml deleted file mode 100644 index 178f15aa4..000000000 --- a/.github/workflows/gitlint.yaml +++ /dev/null @@ -1,25 +0,0 @@ -name: Commit messages check -on: - pull_request: - -jobs: - gitlint: - name: Check commit messages - runs-on: ubuntu-latest - steps: - - name: Checkout repository - uses: actions/checkout@v6 - with: - ref: ${{ github.event.pull_request.head.sha }} - fetch-depth: 0 - - name: Set up Python 3.10 - uses: actions/setup-python@v6 - with: - python-version: "3.10" - - name: Install dependencies - run: | - python -m pip install --upgrade pip - pip install --upgrade gitlint - - name: Lint git commit messages - run: | - gitlint --commits "origin/$GITHUB_BASE_REF.." diff --git a/.github/workflows/hadolint.yaml b/.github/workflows/hadolint.yaml deleted file mode 100644 index 631c50eef..000000000 --- a/.github/workflows/hadolint.yaml +++ /dev/null @@ -1,25 +0,0 @@ -name: Lint Dockerfile -on: - push: - paths: - - resources/Dockerfile - pull_request: - paths: - - resources/Dockerfile - -jobs: - hadolint: - name: Run Hadolint Dockerfile Linter - runs-on: ubuntu-latest - steps: - - name: Checkout code - uses: actions/checkout@v6 - - - name: Lint Dockerfile - uses: hadolint/hadolint-action@master - with: - dockerfile: ./resources/Dockerfile - format: tty - no-fail: false - verbose: true - failure-threshold: info diff --git a/.github/workflows/integration-arm64.yaml b/.github/workflows/integration-arm64.yaml deleted file mode 100644 index d34d28c3c..000000000 --- a/.github/workflows/integration-arm64.yaml +++ /dev/null @@ -1,69 +0,0 @@ -name: Cloud Hypervisor Tests (ARM64) -on: [pull_request, merge_group] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - timeout-minutes: 120 - env: - # Our runner has 80 cores (nproc). - # We limit parallelism only to avoid exhausting disk space and memory - # resources, not to save CPU resources. - PARALLEL_INTEGRATION_TESTS_NUM: 25 - name: Tests (ARM64) - runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || 'bookworm-arm64' }} - steps: - - name: Fix workspace permissions - if: ${{ github.event_name != 'pull_request' }} - run: sudo chown -R runner:runner ${GITHUB_WORKSPACE} - - name: Code checkout - if: ${{ github.event_name != 'pull_request' }} - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - name: Run unit tests (musl) - if: ${{ github.event_name != 'pull_request' }} - run: scripts/dev_cli.sh tests --unit --libc musl - - name: Load openvswitch module - if: ${{ github.event_name != 'pull_request' }} - run: sudo modprobe openvswitch - - name: Run integration tests (musl) - if: ${{ github.event_name != 'pull_request' }} - timeout-minutes: 60 - run: scripts/dev_cli.sh tests --integration --libc musl - - name: Install Azure CLI - if: ${{ github.event_name != 'pull_request' }} - run: | - set -eufo pipefail - sudo apt install -y ca-certificates curl apt-transport-https lsb-release gnupg - curl -sL https://packages.microsoft.com/keys/microsoft.asc | gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/microsoft.gpg > /dev/null - echo "deb [arch=arm64] https://packages.microsoft.com/repos/azure-cli/ bookworm main" | sudo tee /etc/apt/sources.list.d/azure-cli.list - sudo apt update - sudo apt install -y azure-cli - - name: Download Windows image - if: ${{ github.event_name != 'pull_request' }} - shell: bash - run: | - set -eufo pipefail - IMG_BASENAME=windows-11-iot-enterprise-aarch64.raw - IMG_PATH=$HOME/workloads/$IMG_BASENAME - IMG_GZ_PATH=$HOME/workloads/$IMG_BASENAME.gz - IMG_GZ_BLOB_NAME=windows-11-iot-enterprise-aarch64-9-min.raw.gz - cp "scripts/$IMG_BASENAME.sha1" "$HOME/workloads/" - pushd "$HOME/workloads" - if sha1sum "$IMG_BASENAME.sha1" --check; then - exit - fi - popd - mkdir -p "$HOME/workloads" - az storage blob download --container-name private-images --file "$IMG_GZ_PATH" --name "$IMG_GZ_BLOB_NAME" --connection-string "${{ secrets.CH_PRIVATE_IMAGES }}" - gzip -d "$IMG_GZ_PATH" - - name: Run Windows guest integration tests - if: ${{ github.event_name != 'pull_request' }} - timeout-minutes: 30 - run: scripts/dev_cli.sh tests --integration-windows --libc musl - - name: Skipping build for PR - if: ${{ github.event_name == 'pull_request' }} - run: echo "Skipping build for PR" diff --git a/.github/workflows/integration-rate-limiter.yaml b/.github/workflows/integration-rate-limiter.yaml deleted file mode 100644 index b76c35c73..000000000 --- a/.github/workflows/integration-rate-limiter.yaml +++ /dev/null @@ -1,25 +0,0 @@ -name: Cloud Hypervisor Tests (Rate-Limiter) -on: [merge_group, pull_request] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Tests (Rate-Limiter) - runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || 'bare-metal-9950x' }} - env: - AUTH_DOWNLOAD_TOKEN: ${{ secrets.AUTH_DOWNLOAD_TOKEN }} - steps: - - name: Code checkout - if: ${{ github.event_name != 'pull_request' }} - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - name: Run rate-limiter integration tests - if: ${{ github.event_name != 'pull_request' }} - timeout-minutes: 20 - run: scripts/dev_cli.sh tests --integration-rate-limiter - - name: Skipping build for PR - if: ${{ github.event_name == 'pull_request' }} - run: echo "Skipping build for PR" diff --git a/.github/workflows/integration-vfio.yaml b/.github/workflows/integration-vfio.yaml deleted file mode 100644 index b4f2ca2f9..000000000 --- a/.github/workflows/integration-vfio.yaml +++ /dev/null @@ -1,33 +0,0 @@ -name: Cloud Hypervisor Tests (VFIO) -on: [merge_group, pull_request] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Tests (VFIO) - runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || 'vfio-nvidia' }} - env: - AUTH_DOWNLOAD_TOKEN: ${{ secrets.AUTH_DOWNLOAD_TOKEN }} - steps: - - name: Fix workspace permissions - if: ${{ github.event_name != 'pull_request' }} - run: sudo chown -R github-runner:github-runner "${GITHUB_WORKSPACE}" - - name: Code checkout - if: ${{ github.event_name != 'pull_request' }} - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - name: Run VFIO integration tests - if: ${{ github.event_name != 'pull_request' }} - timeout-minutes: 15 - run: scripts/dev_cli.sh tests --integration-vfio - # Most tests are failing with musl see #6790 - # - name: Run VFIO integration tests for musl - # if: ${{ github.event_name != 'pull_request' }} - # timeout-minutes: 15 - # run: scripts/dev_cli.sh tests --integration-vfio --libc musl - - name: Skipping build for PR - if: ${{ github.event_name == 'pull_request' }} - run: echo "Skipping build for PR" diff --git a/.github/workflows/integration-windows.yaml b/.github/workflows/integration-windows.yaml deleted file mode 100644 index 1010ab73e..000000000 --- a/.github/workflows/integration-windows.yaml +++ /dev/null @@ -1,53 +0,0 @@ -name: Cloud Hypervisor Tests (Windows Guest) -on: [merge_group, pull_request] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Tests (Windows Guest) - runs-on: ${{ github.event_name == 'pull_request' && 'ubuntu-latest' || 'garm-jammy-16' }} - steps: - - name: Code checkout - if: ${{ github.event_name != 'pull_request' }} - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - name: Install Docker - if: ${{ github.event_name != 'pull_request' }} - run: | - set -eufo pipefail - sudo apt-get update - sudo apt-get -y install ca-certificates curl gnupg - curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg - sudo chmod a+r /usr/share/keyrings/docker-archive-keyring.gpg - echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null - sudo apt-get update - sudo apt install -y docker-ce docker-ce-cli - - name: Install Azure CLI - if: ${{ github.event_name != 'pull_request' }} - run: | - set -eufo pipefail - sudo apt install -y ca-certificates curl apt-transport-https lsb-release gnupg - curl -sL https://packages.microsoft.com/keys/microsoft.asc | gpg --dearmor | sudo tee /etc/apt/trusted.gpg.d/microsoft.gpg > /dev/null - echo "deb [arch=amd64] https://packages.microsoft.com/repos/azure-cli/ jammy main" | sudo tee /etc/apt/sources.list.d/azure-cli.list - sudo apt update - sudo apt install -y azure-cli - - name: Download Windows image - if: ${{ github.event_name != 'pull_request' }} - run: | - set -eufo pipefail - mkdir $HOME/workloads - az storage blob download --container-name private-images --file "$HOME/workloads/windows-server-2025-amd64-1.raw" --name windows-server-2025-amd64-1.raw --connection-string "${{ secrets.CH_PRIVATE_IMAGES }}" - - name: Run Windows guest integration tests - if: ${{ github.event_name != 'pull_request' }} - timeout-minutes: 15 - run: scripts/dev_cli.sh tests --integration-windows - - name: Run Windows guest integration tests for musl - if: ${{ github.event_name != 'pull_request' }} - timeout-minutes: 15 - run: scripts/dev_cli.sh tests --integration-windows --libc musl - - name: Skipping build for PR - if: ${{ github.event_name == 'pull_request' }} - run: echo "Skipping build for PR" \ No newline at end of file diff --git a/.github/workflows/integration-x86-64.yaml b/.github/workflows/integration-x86-64.yaml deleted file mode 100644 index 38dbcb06f..000000000 --- a/.github/workflows/integration-x86-64.yaml +++ /dev/null @@ -1,54 +0,0 @@ -name: Cloud Hypervisor Tests (x86-64) -on: [pull_request, merge_group] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - timeout-minutes: 80 - env: - # Our runner has 16 cores (nproc). - # We limit parallelism only to avoid exhausting disk space and memory - # resources, not to save CPU resources. - PARALLEL_INTEGRATION_TESTS_NUM: 12 - strategy: - fail-fast: false - matrix: - runner: ['garm-jammy', "garm-jammy-amd"] - libc: ["musl", 'gnu'] - name: Tests (x86-64) - runs-on: ${{ github.event_name == 'pull_request' && !(matrix.runner == 'garm-jammy' && matrix.libc == 'gnu') && 'ubuntu-latest' || format('{0}-16', matrix.runner) }} - steps: - - name: Code checkout - if: ${{ github.event_name != 'pull_request' || (matrix.runner == 'garm-jammy' && matrix.libc == 'gnu') }} - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - name: Install Docker - if: ${{ github.event_name != 'pull_request' || (matrix.runner == 'garm-jammy' && matrix.libc == 'gnu') }} - run: | - set -eufo pipefail - sudo apt-get update - sudo apt-get -y install ca-certificates curl gnupg - curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg - sudo chmod a+r /usr/share/keyrings/docker-archive-keyring.gpg - echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null - sudo apt-get update - sudo apt install -y docker-ce docker-ce-cli - - name: Prepare for VDPA - if: ${{ github.event_name != 'pull_request' || (matrix.runner == 'garm-jammy' && matrix.libc == 'gnu') }} - run: scripts/prepare_vdpa.sh - - name: Run unit tests - if: ${{ github.event_name != 'pull_request' || (matrix.runner == 'garm-jammy' && matrix.libc == 'gnu') }} - run: scripts/dev_cli.sh tests --unit --libc ${{ matrix.libc }} - - name: Load openvswitch module - if: ${{ github.event_name != 'pull_request' || (matrix.runner == 'garm-jammy' && matrix.libc == 'gnu') }} - run: sudo modprobe openvswitch - - name: Run integration tests - if: ${{ github.event_name != 'pull_request' || (matrix.runner == 'garm-jammy' && matrix.libc == 'gnu') }} - timeout-minutes: 80 - run: scripts/dev_cli.sh tests --integration --libc ${{ matrix.libc }} - - name: Skipping build for PR - if: ${{ github.event_name == 'pull_request' && matrix.runner != 'garm-jammy' && matrix.libc != 'gnu' }} - run: echo "Skipping build for PR" diff --git a/.github/workflows/lychee.yaml b/.github/workflows/lychee.yaml deleted file mode 100644 index 105e2e9a6..000000000 --- a/.github/workflows/lychee.yaml +++ /dev/null @@ -1,46 +0,0 @@ -name: Link Check (lychee) -on: pull_request -jobs: - link_check: - name: Link Check - runs-on: ubuntu-latest - steps: - - name: Code checkout - uses: actions/checkout@v6 - with: - # Fetch the entire history so git diff can compare against the base branch - fetch-depth: 0 - - name: Get changed files in PR - id: changed-files - uses: tj-actions/changed-files@v47 # Using a dedicated action for robustness - with: - # Compare the HEAD of the PR with the merge-base (where the PR branches off) - base_sha: ${{ github.event.pull_request.base.sha }} - - # NEW STEP: Print all changed-files outputs for verification - - name: Verify Changed Files - run: | - set -eufo pipefail - echo "--- tj-actions/changed-files Outputs ---" - echo "any_changed: ${{ steps.changed-files.outputs.any_changed }}" - echo "all_changed_files: ${{ steps.changed-files.outputs.all_changed_files }}" - echo "added_files: ${{ steps.changed-files.outputs.added_files }}" - echo "modified_files: ${{ steps.changed-files.outputs.modified_files }}" - echo "deleted_files: ${{ steps.changed-files.outputs.deleted_files }}" - echo "renamed_files: ${{ steps.changed-files.outputs.renamed_files }}" - echo "----------------------------------------" - # This will also show if the all_changed_files string is empty or not - if [ -n "${{ steps.changed-files.outputs.all_changed_files }}" ]; then - echo "Detected changes: all_changed_files output is NOT empty." - else - echo "No changes detected: all_changed_files output IS empty." - fi - - name: Link Availability Check (Diff Only) - # MODIFIED: Only run lychee if the 'all_changed_files' output is not an empty string - if: ${{ steps.changed-files.outputs.all_changed_files != '' }} - uses: lycheeverse/lychee-action@master - with: - # Pass the space-separated list of changed files to lychee - args: --verbose --config .lychee.toml ${{ steps.changed-files.outputs.all_changed_files }} - failIfEmpty: false - fail: true \ No newline at end of file diff --git a/.github/workflows/openapi.yaml b/.github/workflows/openapi.yaml deleted file mode 100644 index 4c179f7e8..000000000 --- a/.github/workflows/openapi.yaml +++ /dev/null @@ -1,14 +0,0 @@ -name: Cloud Hypervisor OpenAPI Validation -on: [pull_request, merge_group] - -jobs: - Validate: - runs-on: ubuntu-latest - container: openapitools/openapi-generator-cli - steps: - - uses: actions/checkout@v6 - - name: Validate OpenAPI - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - run: | - /usr/local/bin/docker-entrypoint.sh validate -i vmm/src/api/openapi/cloud-hypervisor.yaml diff --git a/.github/workflows/package-consistency.yaml b/.github/workflows/package-consistency.yaml deleted file mode 100644 index 7f7808c88..000000000 --- a/.github/workflows/package-consistency.yaml +++ /dev/null @@ -1,33 +0,0 @@ -name: Cloud Hypervisor Consistency -on: [pull_request, merge_group] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Rust VMM Consistency Check - runs-on: ubuntu-latest - steps: - - name: Code checkout - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - - name: Install dependencies - run: sudo apt install -y python3 - - - name: Install Rust toolchain stable - uses: dtolnay/rust-toolchain@stable - with: - toolchain: stable - - - name: Check Rust VMM Package Consistency of root Workspace - run: python3 scripts/package-consistency-check.py github.com/rust-vmm - - - name: Check Rust VMM Package Consistency of fuzz Workspace - run: | - set -eufo pipefail - pushd fuzz - python3 ../scripts/package-consistency-check.py github.com/rust-vmm - popd diff --git a/.github/workflows/quality.yaml b/.github/workflows/quality.yaml deleted file mode 100644 index 1290b0f87..000000000 --- a/.github/workflows/quality.yaml +++ /dev/null @@ -1,179 +0,0 @@ -name: Cloud Hypervisor Quality Checks -on: [pull_request, merge_group] -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}-${{ github.event_name }} - cancel-in-progress: true - -jobs: - build: - name: Quality (clippy) - runs-on: ubuntu-latest - continue-on-error: ${{ matrix.experimental }} - strategy: - fail-fast: false - matrix: - rust: - - beta - - stable - target: - - aarch64-unknown-linux-gnu - - aarch64-unknown-linux-musl - - x86_64-unknown-linux-gnu - - x86_64-unknown-linux-musl - - include: - - rust: beta - experimental: true - - rust: stable - experimental: false - - steps: - - name: Code checkout - uses: actions/checkout@v6 - with: - fetch-depth: 0 - - - name: Install Rust toolchain (${{ matrix.rust }}) - uses: actions-rs/toolchain@v1 - with: - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - override: true - components: clippy - - - name: Bisectability Check (default features) - if: ${{ github.event_name == 'pull_request' && matrix.target == 'x86_64-unknown-linux-gnu' }} - run: | - set -eufo pipefail - commits=$(git rev-list origin/${{ github.base_ref }}..${{ github.sha }}) - for commit in $commits; do git checkout $commit; cargo check --tests --examples --all --target=${{ matrix.target }}; done - git checkout ${{ github.sha }} - - - name: Clippy (kvm) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --no-default-features --tests --examples --features "kvm" -- -D warnings - - - name: Clippy (mshv) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --no-default-features --tests --examples --features "mshv" -- -D warnings - - - name: Clippy (mshv + kvm) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --no-default-features --tests --examples --features "mshv,kvm" -- -D warnings - - - name: Clippy (default features) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --tests --examples -- -D warnings - - - name: Clippy (default features + guest_debug) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --tests --examples --features "guest_debug" -- -D warnings - - - name: Clippy (default features + pvmemcontrol) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --tests --examples --features "pvmemcontrol" -- -D warnings - - - name: Clippy (default features + tracing) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --tests --examples --features "tracing" -- -D warnings - - name: Clippy (default features + fw_cfg) - uses: actions-rs/cargo@v1 - with: - use-cross: ${{ matrix.target != 'x86_64-unknown-linux-gnu' }} - command: clippy - args: --target=${{ matrix.target }} --locked --all --all-targets --tests --examples --features "fw_cfg" -- -D warnings - - - name: Clippy (default features + ivshmem) - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --tests --examples --features "ivshmem" -- -D warnings - - - name: Clippy (sev_snp) - if: ${{ matrix.target == 'x86_64-unknown-linux-gnu' }} - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --no-default-features --tests --examples --features "sev_snp" -- -D warnings - - - name: Clippy (igvm) - if: ${{ matrix.target == 'x86_64-unknown-linux-gnu' }} - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --no-default-features --tests --examples --features "igvm" -- -D warnings - - - name: Clippy (kvm + tdx) - if: ${{ matrix.target == 'x86_64-unknown-linux-gnu' }} - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --no-default-features --tests --examples --features "tdx,kvm" -- -D warnings - - - name: Clippy (kvm + igvm + sev_snp + fw_cfg) - if: ${{ matrix.target == 'x86_64-unknown-linux-gnu' }} - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - cross-version: 3e0957637b49b1bbced23ad909170650c5b70635 - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --no-default-features --tests --examples --features "kvm,igvm,sev_snp,fw_cfg" -- -D warnings - - - name: Clippy (default features + sev_snp + igvm + fw_cfg) - if: ${{ matrix.target == 'x86_64-unknown-linux-gnu' }} - uses: houseabsolute/actions-rust-cross@v1 - with: - command: clippy - cross-version: 3e0957637b49b1bbced23ad909170650c5b70635 - toolchain: ${{ matrix.rust }} - target: ${{ matrix.target }} - args: --locked --all --all-targets --tests --examples --features "sev_snp,igvm,fw_cfg" -- -D warnings - - - name: Check build did not modify any files - run: test -z "$(git status --porcelain)" - - typos: - if: github.event_name == 'pull_request' - name: Typos / Spellcheck - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - # Executes "typos ." - - uses: crate-ci/typos@v1.45.1 diff --git a/.github/workflows/reuse.yaml b/.github/workflows/reuse.yaml deleted file mode 100644 index 39ae87301..000000000 --- a/.github/workflows/reuse.yaml +++ /dev/null @@ -1,12 +0,0 @@ -name: REUSE Compliance Check - -on: [push, pull_request] - -jobs: - reuse: - name: REUSE Compliance Check - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - - name: REUSE Compliance Check - uses: fsfe/reuse-action@v6 diff --git a/.github/workflows/shlint.yaml b/.github/workflows/shlint.yaml deleted file mode 100644 index 068b9930e..000000000 --- a/.github/workflows/shlint.yaml +++ /dev/null @@ -1,20 +0,0 @@ -name: Shell scripts check -on: - pull_request: - merge_group: - push: - branches: - - main - -jobs: - sh-checker: - name: Check shell scripts - runs-on: ubuntu-latest - steps: - - name: Checkout repository - uses: actions/checkout@v6 - - name: Run the shell script checkers - uses: luizm/action-sh-checker@master - env: - SHFMT_OPTS: -i 4 -d - SHELLCHECK_OPTS: -x --source-path scripts diff --git a/.github/workflows/taplo.yaml b/.github/workflows/taplo.yaml deleted file mode 100644 index 24577878b..000000000 --- a/.github/workflows/taplo.yaml +++ /dev/null @@ -1,21 +0,0 @@ -name: Cargo.toml Formatting (taplo) -on: - pull_request: - paths: - - '**/Cargo.toml' - -jobs: - cargo_toml_format: - name: Cargo.toml Formatting - runs-on: ubuntu-latest - steps: - - name: Code checkout - uses: actions/checkout@v6 - - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable - - name: Install build dependencies - run: sudo apt-get update && sudo apt-get -yqq install build-essential libssl-dev - - name: Install taplo - run: cargo install taplo-cli --locked - - name: Check formatting - run: taplo fmt --check