Repository navigation
Conversation
* ci: give the dev branch the same workflow coverage as main Add dev to the push filters of Continuous Integration and OpenSSF Scorecard, and to the pull_request base filter of the Pull Request workflow. Scheduled workflows only ever run on the default branch, so Daily Build and Coverity Scan now fan out over a main/dev matrix, check out the matrix branch explicitly and tag their artifacts with it. Coverity passes the scanned ref and sha to upload-sarif so dev findings are not attributed to main, and Scorecard only publishes results from the default branch, which is all the Scorecard API accepts. * ci: run daily build and coverity on default branch, cache from main and dev
…oud#61) * Add optional VA-API hardware decode of the input stream Introduce an optional top-level "decode" block in the JSON config: "decode": { "hwaccel": true } When enabled, the input bitstream is decoded on the GPU via VA-API instead of the CPU. The device is auto-selected via av_hwdevice_ctx_create(NULL); there is no config key to pin a render node. Hardware decode is strictly best-effort and never fails a run. If FFmpeg was built without --enable-vaapi, no render node is accessible, or the decoder cannot negotiate a GPU surface for the stream, a warning is logged and decoding continues on the CPU. The setting defaults to false, so existing configs are unaffected. Only the decode stage is offloaded. Frames are downloaded back to system memory, leaving the scale/crop/TX path unchanged — MTL transmits from its own DMA buffers, so there is no GPU-to-NIC zero-copy path to target. Notes: - RGB sources (gbrp10le/gbrp12le) can never use VA-API. libavcodec's HEVC decoder only offers a VA-API surface for YUV pixel formats, so those inputs always take the CPU fallback. - Hardware paths are guarded on hw_device_ctx != NULL rather than on hw_pix_fmt. AV_PIX_FMT_NONE is -1, so a zeroed context would otherwise be indistinguishable from YUV420P. - The "(hwaccel=vaapi)" log field reports that the VA-API device opened, which happens before surface-format negotiation. The "surface unavailable for this stream" warning is the authoritative fallback indicator. Also fixes a stray formatting defect in validate_tx_config() where a block comment and the following if statement had been joined onto one line. Adds config parsing and decoder unit tests covering both paths, and documents the option, its prerequisites and its failure modes in README.md. * ci: give the dev branch the same workflow coverage as main (OpenVisualCloud#60) * ci: give the dev branch the same workflow coverage as main Add dev to the push filters of Continuous Integration and OpenSSF Scorecard, and to the pull_request base filter of the Pull Request workflow. Scheduled workflows only ever run on the default branch, so Daily Build and Coverity Scan now fan out over a main/dev matrix, check out the matrix branch explicitly and tag their artifacts with it. Coverity passes the scanned ref and sha to upload-sarif so dev findings are not attributed to main, and Scorecard only publishes results from the default branch, which is all the Scorecard API accepts. * ci: run daily build and coverity on default branch, cache from main and dev * Address PR review feedback on VA-API hardware decode Flatten the config key and harden the decoder fallback paths. Config: - Move the flag from a nested "decode" block to a top-level "hwaccel", as requested in review. - Add find_toplevel_key(), which tracks brace/bracket depth and string state so a match is only accepted at depth 1 and only when followed by ':'. Without this, extract_json_bool() scanned the whole buffer and an "hwaccel" key nested anywhere (a legacy "decode" block, or a session) would silently enable GPU decode. Decoder: - Use ffmpeg_fmt_name() when logging the opened pixel format; av_get_pix_fmt_name() returns NULL for AV_PIX_FMT_NONE. - hwaccel_get_format() now scans for the first format without AV_PIX_FMT_FLAG_HWACCEL instead of assuming fmts[0] is software. - Retry avcodec_open2() on a fresh CPU-only codec context when the first attempt fails with a hardware device attached; only a second failure is fatal. - Latch hwaccel off and reopen the decoder on the CPU after HWACCEL_MAX_XFER_FAILURES consecutive av_hwframe_transfer_data() failures. Previously each failure left got_frame false, which broke out of the decode loop and killed the thread. Tests: - De-nest the existing hwaccel fragments. - Add test_parse_hwaccel_nested_is_ignored as a regression test for the scoping fix. * Add 2K dual-NIC TX config with VA-API hwaccel enabled Two 1280x1440 crops of a 2560x1440 source, one per E610 port (0000:03:00.0 / 0000:03:00.1), yuv422p10le at 30fps. --------- Co-authored-by: Roshan Kumar <roshan.kumar@intel.com>
- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL SARIF uploads already provide scan coverage. - Remove initial 'Clean up previous run' step from ci, coverity, daily_build, and pull_request workflows; GitHub runners start clean.
Replace workspace-relative 'uses: ./...' with GitHub's self-repository 'uses: $/...' form for all local composite actions. This enables fully-pinned policy enforcement and avoids loading actions from runtime filesystem state.
- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx) triggered on PR + push to main/dev, weekly, and manual. Consolidates the approach from the standalone CodeQL PR. - Replace gitleaks-action with a pinned Gitleaks CLI install (checksum verified) running git-history and directory scans; wire Gitleaks Scan into the CI and daily build workflows. Folds in the Gitleaks PR.
…odes Resolves zizmor github-env high-severity findings by passing scan exit codes via step outputs and consuming them through an env: block.
…syntax (OpenVisualCloud#64) * ci: remove on-demand scan and redundant clean step - Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL SARIF uploads already provide scan coverage. - Remove initial 'Clean up previous run' step from ci, coverity, daily_build, and pull_request workflows; GitHub runners start clean. * ci: use self-repository syntax for local actions Replace workspace-relative 'uses: ./...' with GitHub's self-repository 'uses: $/...' form for all local composite actions. This enables fully-pinned policy enforcement and avoids loading actions from runtime filesystem state. * ci: add CodeQL advanced workflow and Gitleaks CLI scan - Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx) triggered on PR + push to main/dev, weekly, and manual. Consolidates the approach from the standalone CodeQL PR. - Replace gitleaks-action with a pinned Gitleaks CLI install (checksum verified) running git-history and directory scans; wire Gitleaks Scan into the CI and daily build workflows. Folds in the Gitleaks PR. * ci(gitleaks): use GITHUB_OUTPUT instead of GITHUB_ENV for scan exit codes Resolves zizmor github-env high-severity findings by passing scan exit codes via step outputs and consuming them through an env: block.
Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.
All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.
* ci: remove on-demand scan and redundant clean step
- Delete scan_on_demand workflow; Coverity (weekly + manual) and CodeQL
SARIF uploads already provide scan coverage.
- Remove initial 'Clean up previous run' step from ci, coverity,
daily_build, and pull_request workflows; GitHub runners start clean.
* ci: use self-repository syntax for local actions
Replace workspace-relative 'uses: ./...' with GitHub's self-repository
'uses: $/...' form for all local composite actions. This enables
fully-pinned policy enforcement and avoids loading actions from runtime
filesystem state.
* ci: add CodeQL advanced workflow and Gitleaks CLI scan
- Add CodeQL Advanced workflow (c-cpp, manual build reusing build-dvledtx)
triggered on PR + push to main/dev, weekly, and manual. Consolidates the
approach from the standalone CodeQL PR.
- Replace gitleaks-action with a pinned Gitleaks CLI install (checksum
verified) running git-history and directory scans; wire Gitleaks Scan
into the CI and daily build workflows. Folds in the Gitleaks PR.
* ci(gitleaks): use GITHUB_OUTPUT instead of GITHUB_ENV for scan exit codes
Resolves zizmor github-env high-severity findings by passing scan exit
codes via step outputs and consuming them through an env: block.
* ci: restore './' prefix for local composite action references
Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.
All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.
---------
Co-authored-by: sunilnom <sunil.nomeshwar.naik@intel.com>
* ci: restore './' prefix for local composite action references
Local action references had been written as '$/.github/actions/...',
which is not valid GitHub Actions syntax; a local action path must
start with './'. GitHub cannot resolve '$/...', and OpenSSF Scorecard
classified all 26 internal references as unpinned third-party actions,
dropping Pinned-Dependencies to 1/10 ("1 out of 34 third-party
GitHubAction dependencies pinned") and the overall score to 8.3.
All remaining external actions are already pinned by SHA, so this
restores Pinned-Dependencies to a passing state.
zizmor 1.30.0 added the self-repository audit, which wants in-repo actions referenced as '$/...'. OpenSSF Scorecard v5.5.0 does not recognise that syntax and counts every such reference as an unpinned third-party action, dropping Pinned-Dependencies to 1/10. Switching between '$/' and './' only trades one report for the other. Keep './' and disable the audit: it is informational (help severity) and these actions are owned by this repository, whereas the Scorecard penalty is a 9-point hit on a published score. zizmor was also installed unpinned in two places, which is how a new release introduced a failing audit without any change to this repo. Pin it to an exact version at both sites; the environment-check pip loop is now version-aware so an already-installed mismatched version is corrected instead of silently accepted.
Revert the workspace-relative './' references back to GitHub's
self-repository syntax ('$/'), which is the more misuse-resistant form:
it cannot resolve to an action cloned into the workspace at runtime, and
GitHub can enforce a fully-pinned policy against it.
This reinstates the OpenSSF Scorecard Pinned-Dependencies penalty, since
Scorecard v5.5.0 does not yet recognise '$/' and counts each reference as
an unpinned third-party action. That trade is accepted deliberately.
The zizmor self-repository suppression is dropped as it is now redundant.
The zizmor version pin is kept.
zizmor was also installed unpinned in two places, which is how a new release introduced a failing audit without any change to this repo. Pin it to an exact version at both sites; the environment-check pip loop is now version-aware so an already-installed mismatched version is corrected instead of silently accepted.
The pinned install broke the environment-check job. Composite bash steps
run with -e and pipefail, so the version probe
HAVE=$(pip3 show "$NAME" | awk '/^Version:/{print $2}')
aborted the step as soon as a package was absent, with stderr suppressed
and no error message. The previous form kept the probe inside an "if"
condition, where -e does not apply.
Restores the unpinned install for both zizmor install sites. Note the
pip install of zizmor itself is long-standing (added in 7619927); only
the pinning and the rewritten probe were recent, and both are reverted
here.
This is a StepSecurity false positive, not a GitHub Actions error. uses: $/.github/actions/analysis/coverity is the new GitHub self-repository syntax. GitHub resolves it to the exact commit currently running, so it is inherently pinned. It requires runner 2.336.0+. StepSecurity has not recognized $/... yet and incorrectly classifies it as an unpinned third-party action. Do not add @sha; that would defeat the self-repository syntax and may be invalid. Recommended action: keep the $/... references and suppress or ignore this StepSecurity finding until StepSecurity adds support. Reverting to ./... would satisfy StepSecurity but reintroduce the zizmor findings.
… audit
Self-repository syntax ('$/...') does not resolve on the runners this
project uses. Every workflow using it failed within ~30 seconds, while
the workspace-relative './' form passes. The two trees differed by
nothing else: 34 'uses:' lines across 6 files, with the intervening
merge touching no .github files at all.
cf600e4 './' PR #3, #4 -> pass
9df7814 '$/' PR #5, #6 -> fail (~30s)
GitHub documents self-repository syntax as requiring an Actions runner
>= 2.336.0, which is the most likely cause.
This restores the workflows and actions to exactly the tree that last
passed CI, and adds a zizmor config disabling the self-repository audit
so the scan stays green. The audit is informational and these actions
are owned by this repository.
No zizmor version pin: pinning is what broke the environment-check job
previously, because the version probe ran outside an 'if' condition and
tripped 'set -e'.
Resolves an add/add conflict in .github/zizmor.yml. Both sides disable the same audit; only the explanatory comment differed, so the resolution merges both rationales (runner incompatibility and Scorecard). dev still carries the zizmor version pin, which merged cleanly because this branch's revert of it postdates the merge base. That pin breaks the environment-check job: the version probe runs outside an 'if' condition and trips 'set -e'. Both affected files are therefore kept at this branch's unpinned versions: .github/actions/environment-check/action.yml .github/actions/analysis/zizmor/action.yml Workflows and actions are unchanged from 49177ec.
Switch the 34 in-repo action references back to '$/', GitHub's self-repository syntax. It is the more misuse-resistant form: it cannot resolve to an action cloned into the workspace at runtime, and GitHub can enforce a fully-pinned policy against it. Known cost: the only trees that have passed CI used './'. Both trees that used '$/' failed within ~30s, with nothing else differing. The cause was never confirmed from a log, and the runner-version theory is weak, since '$/' went GA on 2026-07-30 and GitHub-hosted runners update continuously. CI may therefore stay red until the real cause is identified. The zizmor config is kept. The audit prefers '$/', so disabling it is a no-op today, but it keeps the scan stable if the syntax is revisited. No zizmor version pin: that is what broke environment-check previously.
The file only disabled the self-repository audit. In-repo actions now use '$/', which is the form that audit prefers, so the suppression was a no-op and zizmor passes with no config at all.
dmkarthi
reviewed
Oct 1, 2026
dmkarthi
left a comment
Collaborator
There was a problem hiding this comment.
This PR has changes on HW decoding feature, make a clean push
Contributor
Author
|
taken care in #68 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Checklist
Code Quality
Testing
Review Readiness
Documentation
Security
PR Type
What kind of change does this PR introduce?