Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
version: 2
multi-ecosystem-groups:
gpuagent-build-and-go:
schedule:
interval: weekly
updates:
- package-ecosystem: docker
directory: /tools/build-container
multi-ecosystem-group: gpuagent-build-and-go
open-pull-requests-limit: 1
labels:
- dependencies
- security
- package-ecosystem: gomod
directory: /sw/nic/gpuagent
multi-ecosystem-group: gpuagent-build-and-go
open-pull-requests-limit: 1
labels:
- dependencies
- security
33 changes: 32 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ on:
pull_request:
branches:
- '**'
schedule:
- cron: "0 8 * * 1"
workflow_dispatch:

concurrency:
Expand All @@ -17,6 +19,7 @@ jobs:
timeout-minutes: 60
permissions:
contents: read
security-events: write

steps:
- name: Checkout repository
Expand All @@ -28,13 +31,22 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3

- name: Read Go version
id: go-version
run: |
version=$(awk '$1 == "go" { print $2; exit }' sw/nic/gpuagent/go.mod)
test -n "$version"
echo "version=$version" >> "$GITHUB_OUTPUT"

- name: Build builder container
uses: docker/build-push-action@v6
with:
context: tools/build-container
file: tools/build-container/Dokerfile.rhel9
file: tools/build-container/Dockerfile.rhel9
load: true
tags: gpuagent-builder-rhel:9
build-args: |
GO_VERSION=${{ steps.go-version.outputs.version }}
cache-from: type=gha
cache-to: type=gha,mode=max

Expand All @@ -47,6 +59,25 @@ jobs:
BUILD_DATE=$(date +%Y-%m-%dT%H:%M:%S%z) \
2>&1 | tee build.log

- name: Scan gpuctl with Trivy
uses: aquasecurity/trivy-action@0.35.0
with:
version: v0.74.0
scan-type: fs
scan-ref: sw/nic/build/x86_64/sim/bin/gpuctl
scanners: vuln
severity: HIGH,CRITICAL
ignore-unfixed: true
format: sarif
output: trivy-results.sarif

- name: Upload Trivy results
if: always()
uses: github/codeql-action/upload-sarif@v3.29.6
with:
sarif_file: trivy-results.sarif
category: trivy-gpuctl

- name: Build summary
if: always()
run: |
Expand Down
33 changes: 33 additions & 0 deletions .github/workflows/dependabot-cleanup.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
name: Dependabot Cleanup

on:
pull_request:
types:
- closed

permissions:
contents: write

jobs:
delete-merged-branch:
name: Delete merged Dependabot branch
if: >-
github.event.pull_request.merged &&
github.event.pull_request.head.repo.full_name == github.repository &&
startsWith(github.event.pull_request.head.ref, 'dependabot/')
runs-on: ubuntu-24.04

steps:
- name: Delete branch
uses: actions/github-script@v7.0.1
with:
script: |
try {
await github.rest.git.deleteRef({
owner: context.repo.owner,
repo: context.repo.repo,
ref: `heads/${context.payload.pull_request.head.ref}`,
});
} catch (error) {
if (error.status !== 404) throw error;
}
2 changes: 2 additions & 0 deletions Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -10,10 +10,12 @@ CONTAINER_WORKDIR := /usr/src/github.com/ROCm/gpu-agent
BUILD_DATE ?= $(shell date +%Y-%m-%dT%H:%M:%S%z)
GIT_COMMIT ?= $(shell git rev-list -1 HEAD --abbrev-commit)
BUILD_BASE_IMAGE ?= registry.access.redhat.com/ubi9/ubi:9.4
GO_VERSION ?= $(shell awk '$$1 == "go" { print $$2; exit }' sw/nic/gpuagent/go.mod)

export BUILD_BASE_IMAGE
export GPUAGENT_BLD_CONTAINER_IMAGE
export GPUAGENT_BLD_CONTAINER_IMAGE_UBUNTU
export GO_VERSION

.PHONY: all
all:
Expand Down
31 changes: 31 additions & 0 deletions sw/vendor/go.sum
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8=
github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck=
github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE=
golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA=
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
# compilation and development tools pre-installed.
ARG BUILD_BASE_IMAGE=registry.access.redhat.com/ubi9/ubi:9.8
FROM ${BUILD_BASE_IMAGE}
ARG GO_VERSION=1.25.13

LABEL maintainer="praveenkumar.shanmugam@amd.com"

Expand All @@ -28,13 +29,13 @@

RUN yum install -y sudo

RUN wget https://go.dev/dl/go1.25.13.linux-amd64.tar.gz && \
tar -C /usr/local -xzf go1.25.13.linux-amd64.tar.gz && \
rm -f go1.25.13.linux-amd64.tar.gz
RUN wget https://go.dev/dl/go${GO_VERSION}.linux-amd64.tar.gz && \
tar -C /usr/local -xzf go${GO_VERSION}.linux-amd64.tar.gz && \
rm -f go${GO_VERSION}.linux-amd64.tar.gz

ENV PATH=$PATH:/usr/local/go/bin:/root/go/bin
ENV LD_LIBRARY_PATH=/usr/local/lib:$LD_LIBRARY_PATH

Check warning on line 37 in tools/build-container/Dockerfile.rhel9

View workflow job for this annotation

GitHub Actions / Build

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$LD_LIBRARY_PATH' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/
ENV PKG_CONFIG_PATH=/usr/local/lib/pkgconfig:$PKG_CONFIG_PATH

Check warning on line 38 in tools/build-container/Dockerfile.rhel9

View workflow job for this annotation

GitHub Actions / Build

Variables should be defined before their use

UndefinedVar: Usage of undefined variable '$PKG_CONFIG_PATH' More info: https://docs.docker.com/go/dockerfile/rule/undefined-var/

ADD ./entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
# compilation and development tools pre-installed.
ARG BUILD_BASE_IMAGE=ubuntu:22.04
FROM ${BUILD_BASE_IMAGE}
ARG GO_VERSION=1.25.13

LABEL maintainer="praveenkumar.shanmugam@amd.com"

Expand Down Expand Up @@ -30,9 +31,9 @@ RUN apt-get update && apt-get install -y \

WORKDIR /usr/src/github.com/Rocm/gpu-agent/

RUN wget https://go.dev/dl/go1.25.13.linux-amd64.tar.gz && \
tar -C /usr/local -xzf go1.25.13.linux-amd64.tar.gz && \
rm -f go1.25.13.linux-amd64.tar.gz
RUN wget https://go.dev/dl/go${GO_VERSION}.linux-amd64.tar.gz && \
tar -C /usr/local -xzf go${GO_VERSION}.linux-amd64.tar.gz && \
rm -f go${GO_VERSION}.linux-amd64.tar.gz

ADD ./entrypoint.sh /entrypoint.sh
RUN chmod +x /entrypoint.sh
Expand Down
6 changes: 4 additions & 2 deletions tools/build-container/Makefile
Original file line number Diff line number Diff line change
Expand Up @@ -8,18 +8,20 @@ rhel-builder:
docker build --build-arg USER=$(shell id -un) \
--build-arg GROUP=$(shell id -gn) \
--build-arg BUILD_BASE_IMAGE=$(BUILD_BASE_IMAGE) \
--build-arg GO_VERSION=$(GO_VERSION) \
--build-arg UID=$(shell id -u) \
--build-arg GID=$(shell id -g) \
-t ${GPUAGENT_BLD_CONTAINER_IMAGE} \
. -f Dokerfile.rhel9
. -f Dockerfile.rhel9
echo "dev container build complete : ${GPUAGENT_BLD_CONTAINER_IMAGE}"

# create ubuntu based builder/developer container
ubuntu-builder:
docker build --build-arg USER=$(shell id -un) \
--build-arg GROUP=$(shell id -gn) \
--build-arg GO_VERSION=$(GO_VERSION) \
--build-arg UID=$(shell id -u) \
--build-arg GID=$(shell id -g) \
-t ${GPUAGENT_BLD_CONTAINER_IMAGE_UBUNTU} \
. -f Dokerfile.ubu2204
. -f Dockerfile.ubu2204
echo "builder container build complete : ${GPUAGENT_BLD_CONTAINER_IMAGE_UBUNTU}"
Loading