Skip to content

automation: rebase edera/mainline onto Linus' tree nightly - #11

Closed
kaniini wants to merge 1 commit into
edera/6.18-ltsfrom
automation/mainline-rebase
Closed

kaniini wants to merge 1 commit into
edera/6.18-ltsfrom
automation/mainline-rebase

Conversation

@kaniini

@kaniini kaniini commented Oct 8, 2026

Copy link
Copy Markdown

Ports the nightly upstream rebase from our Xen tree to the kernel, covering edera/mainline only for now: every night at 03:23 UTC, Claude rebases edera/mainline onto torvalds master.

This is one of two PRs with the identical commit:

  • into edera/6.18-lts: the default branch, the only place a scheduled workflow runs from;
  • into edera/mainline: approving a rebase PR runs rebase-land.yml from the PR's merge ref, so mainline needs a copy for approve-to-land to work.

Keep the two copies the same.

How it works

Same shape as Xen. Claude runs with a read-only token and can't push. Its branch leaves the job as a git bundle and is judged independently, using scripts from the commit the run started from:

  • verify-upstream-rebase.sh (unchanged from Xen): on the upstream tip, linear, no commit lost or gained, and the tree moved by exactly the upstream delta;
  • kernel-build.sh: x86_64 and arm64 vmlinux with the Hyper-V, Xen dom0/backend, PV-IOMMU, NUMA affinity and OpenPaX options built in. It fails if olddefconfig drops any of them.

If everything is clean and Claude's report raises no question, edera/mainline is force-pushed. The push is pinned to the old tip, and the old tip is kept as a backup branch. Otherwise the result becomes a rebase/edera-mainline/... PR, and approving it lands it. A night with no result opens an issue.

Differences from Xen

  • Every job clones blobless (filter: blob:none), because full kernel history is several GB.
  • The kernel's .gitignore ignores dot-directories, so new files under .github/ or .automation/ need git add -f. Scratch dirs (.rebase-tools/, .rebase-scratch/) are ignored for free.
  • Upstream is fetched from git.kernel.org.
  • The XSA audit becomes an audit of upstream fixes (Fixes:, CVE, Cc: stable) that touch files the series touches.

Testing

  • Script tests pass, including a new case: the existing merge commit inside the series (from feat(xen): permit ballooning at 2MiB when possible #8) flattens cleanly on the first rebase.
  • actionlint is clean. shellcheck hasn't run yet; the self-test workflow will be its first run.
  • kernel-build.sh builds both current trees on both architectures locally.
  • Not yet run on GitHub. The blobless clone and the kernel.org fetches will be proven by the first workflow_dispatch run.

Needs before it runs

The same repo settings as Xen:

  • REBASE_APP_CLIENT_ID / REBASE_APP_PRIVATE_KEY, with bypass on edera/mainline;
  • the ANTHROPIC_* variables, with a federation rule that accepts a scheduled run on edera/6.18-lts.

The 6.18-lts rebase and the mainline → 6.18 backport flow are written but held back for a later PR.

Port the nightly upstream rebase from the Xen tree to the kernel. Every
night at 03:23 UTC, Claude rebases edera/mainline onto torvalds master,
following .automation/skills/upstream-rebase/SKILL.md: it replays the
series, resolves conflicts, fixes what the replay broke, builds, audits
upstream fixes that meet the series, and writes a report.

The model's own account of its result decides nothing. It runs with a
read-only token; its branch leaves the job as a git bundle and is judged
by scripts taken from the commit the run started from:

- verify-upstream-rebase.sh (unchanged from Xen) proves the series sits
  on the upstream tip, is linear, kept every commit, and moved the tree
  by exactly the upstream delta;
- kernel-build.sh builds x86_64 and arm64 vmlinux with the Hyper-V, Xen
  dom0/backend, PV-IOMMU, NUMA affinity and OpenPaX options built in,
  and fails if olddefconfig drops any of them.

If both pass and the report asks for no decision, edera/mainline is
force-pushed with a lease pinned to the tip the rebase started from, and
the old tip is kept as a backup branch. Otherwise the result goes up as
a pull request carrying the report, and approving it lands it
(rebase-land.yml). A night with no result opens an issue.

Every job clones blobless: the jobs need the kernel's commit graph but
only the contents of the files the series and upstream touch.

The same commit goes on both edera/6.18-lts and edera/mainline: the
schedule runs only from the default branch, but approving a rebase pull
request runs the land workflow from edera/mainline.
@kaniini

kaniini commented Oct 8, 2026

Copy link
Copy Markdown
Author

Mainline copy of this commit: #12. Land both together.

@kaniini

kaniini commented Oct 8, 2026

Copy link
Copy Markdown
Author

Closed: scope is edera/mainline only (#12).

@kaniini kaniini closed this Oct 8, 2026
@kaniini
kaniini deleted the automation/mainline-rebase branch October 8, 2026 19:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant