The memory report builds this pull request merged into master, together
with the nuttx-apps default branch, and nothing else, so a companion or
predecessor pull request it declares is absent. For a breaking change the
target then fails to build and no report is produced at all, even though
the Build workflow already tests the declared sources through Depends-On.
Apply the declared dependencies before building, reusing the parser and
the fetch/cherry-pick sequence that build.yml uses, and mapping each
repository to its checkout exactly as build.yml does. A stacked nuttx
dependency is no more optional than an apps one: a pull request that uses
an API its predecessor introduces does not build without it.
As build.yml does, read the description through the API rather than
trusting the event payload, so that a manual re-run after editing a
Depends-On line applies the current declaration instead of the one the run
was created with. Unlike build.yml, a failed read stops the job rather
than falling back to the payload: build.yml resolves this once and hands
every target the same tree, while this job runs per target, so a fallback
could leave targets on different declarations while their results are
filed under one SHA.
A declared dependency that cannot be applied fails the job, and so does a
missing parser, a parser crash, or a status this step does not recognise:
each of those means the declaration was never evaluated, and continuing
would measure a combination nobody asked for. build.yml fails Fetch-Source
on the same conditions, and no other step in this job carries
continue-on-error, so falling back silently would be inconsistent with
both. A declaration that parses to nothing valid only warns, again
matching build.yml.
Forward the parser's warnings too. --print-state prints only the state, so
an entry the parser drops -- an unsupported repository, say -- would
otherwise leave no trace here at all, although build.yml annotates it, and
the source set named below would be silently incomplete.
The report is filed under the pull request head SHA rather than the SHA of
the tree that was built, so the measurement cannot be reproduced from that
SHA alone and cannot be split per dependency. That limits provenance, not
the measurement: a combined result is what the declaration asks for, and a
regression that only appears in combination is still a regression. Name
the whole source set in the step summary so the reader knows which heads
went into the number.
Note in the parser that the --print-state output is a parsed contract; the
edit gate that used to be its only caller is gone.
Update the CI documentation to match. Its Pull Request Dependencies
section attributes dependency application to build.yml's Fetch-Source
job alone, so after this change it would read as if the memory report
measured the normal source selection. Cross-reference the two sections
rather than restating the rules, which stay shared.
Signed-off-by: zhangning21 <zhangning21@xiaomi.com>
Install the published NTFC 0.0.3 package from PyPI instead of the
temporary upstream main dependency.
Keep the retry loop and fail the job when all installation attempts are
exhausted.
Signed-off-by: raiden00pl <raiden00@railab.me>
nuttx-ntfc-testing's release-0.0.1 tag pins ntfc.yaml's citest
requirement to CONFIG_INIT_ENTRYPOINT=nsh_main, so any sim/citest
defconfig that switches to a different init entrypoint (e.g. nxinit's
init_main) fails CI with:
OSError: Missing kconfig dependency: ['CONFIG_INIT_ENTRYPOINT', 'nsh_main']
Maintainer raiden00pl cut nuttx-ntfc-testing release-0.0.2, which drops
that CONFIG_INIT_ENTRYPOINT requirement from ntfc.yaml, and requested
both nuttx and nuttx-apps workflows be updated to it:
https://github.com/apache/nuttx-ntfc-testing/issues/7#issuecomment-5480486089
Only the `git clone -b release-0.0.1` line is changed; the unrelated
`ntfc==0.0.1` PyPI package pin is untouched.
Assisted-by: opencode-agent/claude-sonnet-5
Signed-off-by: wangjianyu3 <wangjianyu3@xiaomi.com>
The Depends-On feature (commit e73f7f7d0e) made the Build workflow
trigger on PR description edits. A gate job checks whether the edit
changed any Depends-On declaration: if yes, the build jobs run again
with the new dependencies; on any other edit the gate skips all build
jobs.
The gate has a side effect that breaks PR check results. Skipped jobs
still register check results on the PR, and the PR checks view shows
the newest check run of each name. So after any description edit the
PR shows "skipped" for every build check instead of the pass/fail
from the real run. Re-running that newest run only repeats the skip,
so the real results never come back. This can also hide a red X from
a failed build.
Fix by not triggering Build on description edits at all: remove the
"edited" event type and the gate job.
Depends-On keeps working: dependencies are read from the description
at the start of every run against master, as before. Fetch-Source now
re-reads the description through the API instead of using the copy
stored in the event payload, so every run uses the current Depends-On
state no matter how it was triggered.
After editing a Depends-On line, retrigger CI by any of:
- pushing new or rebased commits to the PR branch
- closing and reopening the PR
- pressing "Re-run all jobs" on the existing Build run
A description edit alone no longer triggers anything, which is
exactly the behavior that corrupted the PR check results.
Update Documentation/testing/nuttx-ci.rst accordingly.
Same change as in nuttx-apps; both repos received the gate from the
same Depends-On feature.
Signed-off-by: raiden00pl <raiden00@railab.me>
Assisted-by: Claude Code
The documentation job installs with `pipenv install`, which does not honour
the committed Pipfile.lock. Every run in the logs prints "Locking
dependencies..." and "Updated Pipfile.lock" and then installs from the set it
has just re-resolved, so each build takes whatever PyPI resolves that day
rather than what the lock file names.
On the evening of 2026-08-03 that resolution produced a virtualenv without
packaging, and four unrelated pull requests failed identically, before Sphinx
had read a single file:
File ".../sphinx/extension.py", line 7, in <module>
from packaging.version import InvalidVersion, Version
ModuleNotFoundError: No module named 'packaging'
`pipenv sync` installs exactly what Pipfile.lock names and never re-resolves,
which is what the lock file is for. The committed lock covers all fourteen
packages the Pipfile asks for, packaging included, so it is complete enough to
install from as it stands.
The workflow also ran only for changes under Documentation/, so a change to the
documentation build was never exercised by the build it changed. It now
triggers on its own path as well, which is what tests this commit.
Assisted-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Signed-off-by: Marco Casaroli <marco.casaroli@gmail.com>
Allow pull requests targeting master to declare same- and
cross-repository dependencies. Parse declarations with a tested Python
helper, apply exact dependency commits before the existing build matrix,
and rerun heavy CI only when an edited description changes the dependency
state.
Keep fork builds read-only and use a trusted workflow_run to validate
artifacts and post per-build dependency results. Document the supported
declaration forms and operational limits.
Assisted-by: Kiro:gpt-5.6-sol
Signed-off-by: zhangning21 <zhangning21@xiaomi.com>
Document PBKDF2-HMAC-SHA256 ROMFS passwd generation and update board
Kconfig help text accordingly. Set the documented sim/login CI credential
in GitHub Actions.
Enable CONFIG_CODECS_BASE64 and CONFIG_NETUTILS_CODECS on sim:dropbear for
link compatibility with dropbear's bundled libtomcrypt.
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
The MemBrowse analyze job intermittently failed unpacking the CI image
with "no space left on device". Free /usr/local/lib/android before the
docker pull, mirroring .github/workflows/build.yml.
Signed-off-by: Michael Rogov Papernov <michael@membrowse.com>
Fixed MemBrowse report action to detect DOC only changes based on
comparing the forked point in the master with the PR, and not the
current master.
Signed-off-by: Michael Rogov Papernov <michael@membrowse.com>
Support NUTTX_ROMFS_PASSWD_PASSWORD via update_romfs_password.sh for
configs that enable ROMFS passwd without a defconfig password (sim/login
CI). Enable RANDOMIZE_KEYS in sim/login defconfig. Update mkpasswd.c
header, platform docs, and the mkpasswd_autogen guide.
Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
Update the linker script path in membrowse-targets.json and
the cuncurrency condition, to prevent breaking the commit chain
Signed-off-by: Michael Rogov Papernov <michael@membrowse.com>
Fix
====================================================================================
Cmake in present: sim\windows
Configuration/Tool: sim\windows
2026-06-02 12:57:35
------------------------------------------------------------------------------------
Cleaning...
Skipping: sim\windows
------------------------------------------------------------------------------------
End: 2026-06-02 12:57:35
====================================================================================
The "windows-latest" and “windows-2025” labels in GitHub Actions will be migrated to use Visual Studio 2026 by default. Customers needing Visual Studio 2022 must migrate to the windows-2022 image.
https://github.com/actions/runner-images/issues/14017
Signed-off-by: simbit18 <simbit18@gmail.com>
github infra is not stable so even "git clone" from github repos can fail with error: 500.
With this commit we try to clone repo few more times.
Signed-off-by: raiden00pl <raiden00@railab.me>
Git
- Enabled long path support by setting the core.longpaths setting to true.
Fix
Cloning into 'esp-hal-3rdparty'...
HEAD is now at 5d8324708f5 Enable using `esp_timer` on RISC-V devices
error: unable to create file tf-psa-crypto/drivers/everest/include/tf-psa-crypto/private/everest/kremlib/FStar_UInt64_FStar_UInt32_FStar_UInt16_FStar_UInt8.h: Filename too long
fatal: Unable to checkout '582ff482038db6e4010dbf6f943d97b05ad06ea5' in submodule path 'components/mbedtls/mbedtls'
error: unable to create file tf-psa-crypto/drivers/everest/include/tf-psa-crypto/private/everest/kremlib/FStar_UInt64_FStar_UInt32_FStar_UInt16_FStar_UInt8.h: Filename too long
fatal: Could not reset index file to revision 'HEAD'.
Signed-off-by: simbit18 <simbit18@gmail.com>
This is necessary because new defconfig were recently added to
Xtensa-based Espressif SoCs and the build job may exceed 2 hours.
In order to avoid increasing job timeout, a specific job for each
supported SoC (ESP32, ESP32-S2 and ESP32-S3) was created instead.
Signed-off-by: Tiago Medicci Serrano <tiago.medicci@espressif.com>
All CI Builds have been failing since 18 hours ago. That's because ASF Infrastructure Team has mandated that we use the Specific Versions of GitHub Actions for Docker, stated below:
- https://github.com/apache/infrastructure-actions/blob/main/actions.yml
- Which generates: https://github.com/apache/infrastructure-actions/blob/main/approved_patterns.yml
```yaml
docker/build-push-action:
10e90e3645eae34f1e60eeb005ba3a3d33f178e8:
tag: v6.19.2
docker/login-action:
c94ce9fb468520275223c153574b00df6fe4bcc9:
tag: v3.7.0
docker/metadata-action:
c299e40c65443455700f0fdfc63efafe5b349051:
tag: v5.10.0
docker/setup-buildx-action:
8d2750c68a42422c14e847fe6c8ac0403b4cbd6f:
tag: v3.12.0
```
This PR reverts our GitHub Actions for Docker to the versions stated above.
Signed-off-by: Lup Yuen Lee <luppy@appkaki.com>
- Updated the check workflow to conditionally include a '-b' option for breaking change enforcement based on PR labels.
- Modified the checkpatch script to support reading commit messages from stdin when using the '-m -g' flags.
- Improved usage instructions to clarify the new stdin option for commit message checks.
Signed-off-by: Arjav Patel <arjav1528@gmail.com>
Our New PR Labeler incorrectly labels the Changed Files for Build System. Here is a Sample PR that contains changes for Arm32 CMake and Makefile: https://github.com/lupyuen6/nuttx/pull/59
```
arch/arm/CMakeLists.txt
arch/arm/Makefile
```
But our PR Labeler incorrectly labels the above as `Area: Build system, Arch: Arm`, which triggers a Complete CI Build across All Architectures (according to arch.yml). The correct label should be `Arch: Arm`, which will trigger only the Arm32 Build: https://github.com/lupyuen8/nuttx/pull/1
This PR fixes the PR Labeling. The New PR Labeler is explained here:
- https://lupyuen.org/articles/prtarget
- https://github.com/apache/nuttx/issues/18359
`.github/workflows/labeler.yml`: Changed the Regex Pattern. Now we match the Start Of Line and End Of Line.
Signed-off-by: Lup Yuen Lee <luppy@appkaki.com>
ASF Infrastructure Team has flagged a GitHub Actions workflow policy violation, inside our PR Labeling. We must remove pull_request_target before 6 Apr 2026, or ASF Infra will turn off all GitHub Builds: https://github.com/apache/nuttx/issues/18359
This PR reimplements the PR Labeling with two triggers: pull_request and workflow_run. We no longer need pull_request_target, which is an unsafe trigger and may introduce security vulnerabilities.
GitHub Actions `codelytv/pr-size-labeler` and `actions/labeler` don't work with the pull_request trigger, so we replaced them with our own code. The implementation is explained here: https://github.com/apache/nuttx/issues/18359
### Modified Files
`.github/workflows/labeler.yml`: Changed the (read-write) pull_request_target trigger to (read-only) pull_request trigger. Compute the Size Label (e.g. Size: XS) and Arch Labels (e.g. Arch: arm). Save the PR Labels into a PR Artifact.
`.github/labeler.yml`: Added comment to clarify that NuttX PR Labeler only supports a subset of the `actions/labeler` syntax: `changed-files` and `any-glob-to-any-file`
### New Files
`.github/workflows/pr_labeler.yml`: Contains the workflow_run trigger, which is executed upon completion of the pull_request trigger. Download the PR Labels from the PR Artifact. Write the PR Labels into the PR.
Signed-off-by: Lup Yuen Lee <luppy@appkaki.com>