Skip to content

Ci/simplify workflows - #65

Closed
roshan-ku wants to merge 22 commits into
OpenVisualCloud:mainfrom
roshan-ku:ci/simplify-workflows
Closed

roshan-ku wants to merge 22 commits into
OpenVisualCloud:mainfrom
roshan-ku:ci/simplify-workflows

Conversation

@roshan-ku

Copy link
Copy Markdown
Contributor

Description

Checklist

Code Quality

  • Code follows project style guidelines
  • No unnecessary debug logs or commented-out code
  • No hardcoded values / secrets

Testing

  • Unit test added/modified accordingly
  • Perform manual basic sanity testing at system level

Review Readiness

  • PR title and description are clear and meaningful
  • Story/Task IDs are linked

Documentation

  • README or relevant docs updated (if applicable)

Security

  • No sensitive data exposed (keys, passwords, tokens)
  • Input validation added where needed

PR Type

What kind of change does this PR introduce?

  • Bugfix
  • Feature
  • Code style update (formatting, local variables)
  • Refactoring (no functional changes, no api changes)
  • Documentation content changes
  • Testing
  • Other... Please describe:

roshan-ku and others added 22 commits September 23, 2026 13:55
* ci: give the dev branch the same workflow coverage as main

Add dev to the push filters of Continuous Integration and OpenSSF
Scorecard, and to the pull_request base filter of the Pull Request
workflow.

Scheduled workflows only ever run on the default branch, so Daily Build
and Coverity Scan now fan out over a main/dev matrix, check out the
matrix branch explicitly and tag their artifacts with it. Coverity
passes the scanned ref and sha to upload-sarif so dev findings are not
attributed to main, and Scorecard only publishes results from the
default branch, which is all the Scorecard API accepts.

* ci: run daily build and coverity on default branch, cache from main and dev
…oud#61)

* Add optional VA-API hardware decode of the input stream

Introduce an optional top-level "decode" block in the JSON config:

    "decode": { "hwaccel": true }

When enabled, the input bitstream is decoded on the GPU via VA-API
instead of the CPU. The device is auto-selected via
av_hwdevice_ctx_create(NULL); there is no config key to pin a render
node.

Hardware decode is strictly best-effort and never fails a run. If
FFmpeg was built without --enable-vaapi, no render node is accessible,
or the decoder cannot negotiate a GPU surface for the stream, a warning
is logged and decoding continues on the CPU. The setting defaults to
false, so existing configs are unaffected.

Only the decode stage is offloaded. Frames are downloaded back to
system memory, leaving the scale/crop/TX path unchanged — MTL
transmits from its own DMA buffers, so there is no GPU-to-NIC
zero-copy path to target.

Notes:

- RGB sources (gbrp10le/gbrp12le) can never use VA-API. libavcodec's
  HEVC decoder only offers a VA-API surface for YUV pixel formats, so
  those inputs always take the CPU fallback.
- Hardware paths are guarded on hw_device_ctx != NULL rather than on
  hw_pix_fmt. AV_PIX_FMT_NONE is -1, so a zeroed context would
  otherwise be indistinguishable from YUV420P.
- The "(hwaccel=vaapi)" log field reports that the VA-API device
  opened, which happens before surface-format negotiation. The
  "surface unavailable for this stream" warning is the authoritative
  fallback indicator.

Also fixes a stray formatting defect in validate_tx_config() where a
block comment and the following if statement had been joined onto one
line.

Adds config parsing and decoder unit tests covering both paths, and
documents the option, its prerequisites and its failure modes in
README.md.

* ci: give the dev branch the same workflow coverage as main (OpenVisualCloud#60)

* ci: give the dev branch the same workflow coverage as main

Add dev to the push filters of Continuous Integration and OpenSSF
Scorecard, and to the pull_request base filter of the Pull Request
workflow.

Scheduled workflows only ever run on the default branch, so Daily Build
and Coverity Scan now fan out over a main/dev matrix, check out the
matrix branch explicitly and tag their artifacts with it. Coverity
passes the scanned ref and sha to upload-sarif so dev findings are not
attributed to main, and Scorecard only publishes results from the
default branch, which is all the Scorecard API accepts.

* ci: run daily build and coverity on default branch, cache from main and dev

* Address PR review feedback on VA-API hardware decode

Flatten the config key and harden the decoder fallback paths.

Config:
- Move the flag from a nested "decode" block to a top-level "hwaccel",
  as requested in review.
- Add find_toplevel_key(), which tracks brace/bracket depth and string
  state so a match is only accepted at depth 1 and only when followed
  by ':'. Without this, extract_json_bool() scanned the whole buffer
  and an "hwaccel" key nested anywhere (a legacy "decode" block, or a
  session) would silently enable GPU decode.

Decoder:
- Use ffmpeg_fmt_name() when logging the opened pixel format;
  av_get_pix_fmt_name() returns NULL for AV_PIX_FMT_NONE.
- hwaccel_get_format() now scans for the first format without
  AV_PIX_FMT_FLAG_HWACCEL instead of assuming fmts[0] is software.
- Retry avcodec_open2() on a fresh CPU-only codec context when the
  first attempt fails with a hardware device attached; only a second
  failure is fatal.
- Latch hwaccel off and reopen the decoder on the CPU after
  HWACCEL_MAX_XFER_FAILURES consecutive av_hwframe_transfer_data()
  failures. Previously each failure left got_frame false, which broke
  out of the decode loop and killed the thread.

Tests:
- De-nest the existing hwaccel fragments.
- Add test_parse_hwaccel_nested_is_ignored as a regression test for
  the scoping fix.

* Add 2K dual-NIC TX config with VA-API hwaccel enabled

Two 1280x1440 crops of a 2560x1440 source, one per E610 port
(0000:03:00.0 / 0000:03:00.1), yuv422p10le at 30fps.

---------

Co-authored-by: Roshan Kumar <roshan.kumar@intel.com>
- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL
  SARIF uploads already provide scan coverage.
- Remove initial 'Clean up previous run' step from ci, coverity,
  daily_build, and pull_request workflows; GitHub runners start clean.
Replace workspace-relative 'uses: ./...' with GitHub's self-repository
'uses: $/...' form for all local composite actions. This enables
fully-pinned policy enforcement and avoids loading actions from runtime
filesystem state.
- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx)
  triggered on PR + push to main/dev, weekly, and manual. Consolidates the
  approach from the standalone CodeQL PR.
- Replace gitleaks-action with a pinned Gitleaks CLI install (checksum
  verified) running git-history and directory scans; wire Gitleaks Scan
  into the CI and daily build workflows. Folds in the Gitleaks PR.
…odes

Resolves zizmor github-env high-severity findings by passing scan exit
codes via step outputs and consuming them through an env: block.
…syntax (OpenVisualCloud#64)

* ci: remove on-demand scan and redundant clean step

- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL
  SARIF uploads already provide scan coverage.
- Remove initial 'Clean up previous run' step from ci, coverity,
  daily_build, and pull_request workflows; GitHub runners start clean.

* ci: use self-repository syntax for local actions

Replace workspace-relative 'uses: ./...' with GitHub's self-repository
'uses: $/...' form for all local composite actions. This enables
fully-pinned policy enforcement and avoids loading actions from runtime
filesystem state.

* ci: add CodeQL advanced workflow and Gitleaks CLI scan

- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx)
  triggered on PR + push to main/dev, weekly, and manual. Consolidates the
  approach from the standalone CodeQL PR.
- Replace gitleaks-action with a pinned Gitleaks CLI install (checksum
  verified) running git-history and directory scans; wire Gitleaks Scan
  into the CI and daily build workflows. Folds in the Gitleaks PR.

* ci(gitleaks): use GITHUB_OUTPUT instead of GITHUB_ENV for scan exit codes

Resolves zizmor github-env high-severity findings by passing scan exit
codes via step outputs and consuming them through an env: block.
Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.

All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.
* ci: remove on-demand scan and redundant clean step

- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL
  SARIF uploads already provide scan coverage.
- Remove initial 'Clean up previous run' step from ci, coverity,
  daily_build, and pull_request workflows; GitHub runners start clean.

* ci: use self-repository syntax for local actions

Replace workspace-relative 'uses: ./...' with GitHub's self-repository
'uses: $/...' form for all local composite actions. This enables
fully-pinned policy enforcement and avoids loading actions from runtime
filesystem state.

* ci: add CodeQL advanced workflow and Gitleaks CLI scan

- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx)
  triggered on PR + push to main/dev, weekly, and manual. Consolidates the
  approach from the standalone CodeQL PR.
- Replace gitleaks-action with a pinned Gitleaks CLI install (checksum
  verified) running git-history and directory scans; wire Gitleaks Scan
  into the CI and daily build workflows. Folds in the Gitleaks PR.

* ci(gitleaks): use GITHUB_OUTPUT instead of GITHUB_ENV for scan exit codes

Resolves zizmor github-env high-severity findings by passing scan exit
codes via step outputs and consuming them through an env: block.

* ci: restore './' prefix for local composite action references

Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.

All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.

---------

Co-authored-by: sunilnom <sunil.nomeshwar.naik@intel.com>
* ci: restore './' prefix for local composite action references

Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.

All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.
zizmor 1.30.0 added the self-repository audit, which wants in-repo
actions referenced as '$/...'. OpenSSF Scorecard v5.5.0 does not
recognise that syntax and counts every such reference as an unpinned
third-party action, dropping Pinned-Dependencies to 1/10. Switching
between '$/' and './' only trades one report for the other.

Keep './' and disable the audit: it is informational (help severity)
and these actions are owned by this repository, whereas the Scorecard
penalty is a 9-point hit on a published score.

zizmor was also installed unpinned in two places, which is how a new
release introduced a failing audit without any change to this repo.
Pin it to an exact version at both sites; the environment-check pip
loop is now version-aware so an already-installed mismatched version
is corrected instead of silently accepted.
Revert the workspace-relative './' references back to GitHub's
self-repository syntax ('$/'), which is the more misuse-resistant form:
it cannot resolve to an action cloned into the workspace at runtime, and
GitHub can enforce a fully-pinned policy against it.

This reinstates the OpenSSF Scorecard Pinned-Dependencies penalty, since
Scorecard v5.5.0 does not yet recognise '$/' and counts each reference as
an unpinned third-party action. That trade is accepted deliberately.

The zizmor self-repository suppression is dropped as it is now redundant.
The zizmor version pin is kept.
zizmor was also installed unpinned in two places, which is how a new
release introduced a failing audit without any change to this repo.
Pin it to an exact version at both sites; the environment-check pip
loop is now version-aware so an already-installed mismatched version
is corrected instead of silently accepted.
The pinned install broke the environment-check job. Composite bash steps
run with -e and pipefail, so the version probe

  HAVE=$(pip3 show "$NAME" | awk '/^Version:/{print $2}')

aborted the step as soon as a package was absent, with stderr suppressed
and no error message. The previous form kept the probe inside an "if"
condition, where -e does not apply.

Restores the unpinned install for both zizmor install sites. Note the
pip install of zizmor itself is long-standing (added in 7619927); only
the pinning and the rewritten probe were recent, and both are reverted
here.
This is a StepSecurity false positive, not a GitHub Actions error.
 
uses: $/.github/actions/analysis/coverity is the new GitHub self-repository syntax. GitHub resolves it to the exact commit currently running, so it is inherently pinned. It requires runner 2.336.0+.
 
StepSecurity has not recognized $/... yet and incorrectly classifies it as an unpinned third-party action. Do not add @sha; that would defeat the self-repository syntax and may be invalid.
 
Recommended action: keep the $/... references and suppress or ignore this StepSecurity finding until StepSecurity adds support. Reverting to ./... would satisfy StepSecurity but reintroduce the zizmor findings.
… audit

Self-repository syntax ('$/...') does not resolve on the runners this
project uses. Every workflow using it failed within ~30 seconds, while
the workspace-relative './' form passes. The two trees differed by
nothing else: 34 'uses:' lines across 6 files, with the intervening
merge touching no .github files at all.

  cf600e4  './'  PR #3, #4  -> pass
  9df7814  '$/'  PR #5, #6  -> fail (~30s)

GitHub documents self-repository syntax as requiring an Actions runner
>= 2.336.0, which is the most likely cause.

This restores the workflows and actions to exactly the tree that last
passed CI, and adds a zizmor config disabling the self-repository audit
so the scan stays green. The audit is informational and these actions
are owned by this repository.

No zizmor version pin: pinning is what broke the environment-check job
previously, because the version probe ran outside an 'if' condition and
tripped 'set -e'.
Resolves an add/add conflict in .github/zizmor.yml. Both sides disable
the same audit; only the explanatory comment differed, so the resolution
merges both rationales (runner incompatibility and Scorecard).

dev still carries the zizmor version pin, which merged cleanly because
this branch's revert of it postdates the merge base. That pin breaks the
environment-check job: the version probe runs outside an 'if' condition
and trips 'set -e'. Both affected files are therefore kept at this
branch's unpinned versions:

  .github/actions/environment-check/action.yml
  .github/actions/analysis/zizmor/action.yml

Workflows and actions are unchanged from 49177ec.
Switch the 34 in-repo action references back to '$/', GitHub's
self-repository syntax. It is the more misuse-resistant form: it cannot
resolve to an action cloned into the workspace at runtime, and GitHub can
enforce a fully-pinned policy against it.

Known cost: the only trees that have passed CI used './'. Both trees that
used '$/' failed within ~30s, with nothing else differing. The cause was
never confirmed from a log, and the runner-version theory is weak, since
'$/' went GA on 2026-07-30 and GitHub-hosted runners update continuously.
CI may therefore stay red until the real cause is identified.

The zizmor config is kept. The audit prefers '$/', so disabling it is a
no-op today, but it keeps the scan stable if the syntax is revisited.

No zizmor version pin: that is what broke environment-check previously.
The file only disabled the self-repository audit. In-repo actions now use
'$/', which is the form that audit prefers, so the suppression was a no-op
and zizmor passes with no config at all.

@dmkarthi dmkarthi left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR has changes on HW decoding feature, make a clean push

@roshan-ku

roshan-ku commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

taken care in #68

@roshan-ku roshan-ku closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants