Pull requests to resolute-qcom-devel are build-checked by premerge-pr.yml. Pull requests to main are not: nothing on main builds a kernel on pull_request.
Changes to main carry the wider blast radius. premerge-pr.yml and the nightly both call build-kernel.yml@main, so a broken workflow merged to main breaks every devel PR check and the next nightly. Recent CI changes have had to be validated by hand instead: #108 needed a temporary ref pin and a manual dispatch, and #129 and #141 were verified only through apt-get build-dep.
Proposal: a build-only check on pull requests to main, building resolute-qcom-devel with the PR's workflow and scripts. No distro-images dispatch and no S3 upload.
- Call
build-kernel.yml by local path rather than @main, so the PR's version is what runs.
- Make the CI scripts ref an input defaulting to
main, so the check can run the PR's scripts without loosening the default pin.
- Limit to changes under
.github/workflows/ and scripts/ so docs-only PRs skip it, and keep it non-required at first, since a path-skipped required check never reports.
- Guard the job to same-repository pull requests. On
pull_request the workflow definition comes from the PR itself, so this prevents accidental runs rather than enforcing anything; fork approval settings remain the boundary for the self-hosted runner.
- Build the
qcom flavour with dbgsym disabled, matching premerge-pr.yml.
Pull requests to
resolute-qcom-develare build-checked bypremerge-pr.yml. Pull requests tomainare not: nothing onmainbuilds a kernel onpull_request.Changes to
maincarry the wider blast radius.premerge-pr.ymland the nightly both callbuild-kernel.yml@main, so a broken workflow merged tomainbreaks every devel PR check and the next nightly. Recent CI changes have had to be validated by hand instead: #108 needed a temporary ref pin and a manual dispatch, and #129 and #141 were verified only throughapt-get build-dep.Proposal: a build-only check on pull requests to
main, buildingresolute-qcom-develwith the PR's workflow and scripts. No distro-images dispatch and no S3 upload.build-kernel.ymlby local path rather than@main, so the PR's version is what runs.main, so the check can run the PR's scripts without loosening the default pin..github/workflows/andscripts/so docs-only PRs skip it, and keep it non-required at first, since a path-skipped required check never reports.pull_requestthe workflow definition comes from the PR itself, so this prevents accidental runs rather than enforcing anything; fork approval settings remain the boundary for the self-hosted runner.qcomflavour withdbgsymdisabled, matchingpremerge-pr.yml.