MAINTAINERS | 2 - .gitlab-ci.d/opensbi.yml | 88 --------------------------------- .gitlab-ci.d/opensbi/Dockerfile | 34 ------------- .gitlab-ci.d/qemu-project.yml | 1 - 4 files changed, 125 deletions(-) delete mode 100644 .gitlab-ci.d/opensbi.yml delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
The OpenSBI firmware build job follows the same pattern as the EDK2 job
[1] that was removed earlier [2]: it exists to produce firmware binaries
from CI artifacts, but those outputs are not consumed by the tree.
Remove the job definition and its project include to avoid maintaining
bitrotting container and firmware build logic.
[1] 71920809ceab ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries")
[2] 690ceb71936f ("gitlab-ci: Remove job building EDK2 firmware binaries")
Signed-off-by: Bin Meng <bin.meng@processmission.com>
---
MAINTAINERS | 2 -
.gitlab-ci.d/opensbi.yml | 88 ---------------------------------
.gitlab-ci.d/opensbi/Dockerfile | 34 -------------
.gitlab-ci.d/qemu-project.yml | 1 -
4 files changed, 125 deletions(-)
delete mode 100644 .gitlab-ci.d/opensbi.yml
delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
diff --git a/MAINTAINERS b/MAINTAINERS
index 97dcc78ded..59707bf2a7 100644
--- a/MAINTAINERS
+++ b/MAINTAINERS
@@ -4117,8 +4117,6 @@ R: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
L: qemu-riscv@nongnu.org
S: Supported
F: pc-bios/opensbi-*
-F: .gitlab-ci.d/opensbi.yml
-F: .gitlab-ci.d/opensbi/
Clock framework
M: Luc Michel <luc@lmichel.fr>
diff --git a/.gitlab-ci.d/opensbi.yml b/.gitlab-ci.d/opensbi.yml
deleted file mode 100644
index 42f137d624..0000000000
--- a/.gitlab-ci.d/opensbi.yml
+++ /dev/null
@@ -1,88 +0,0 @@
-# All jobs needing docker-opensbi must use the same rules it uses.
-.opensbi_job_rules:
- rules:
- # Forks don't get pipelines unless QEMU_CI=1 or QEMU_CI=2 is set
- - if: '$QEMU_CI != "1" && $QEMU_CI != "2" && $CI_PROJECT_NAMESPACE != "qemu-project"'
- when: never
-
- # In forks, if QEMU_CI=1 is set, then create manual job
- # if any files affecting the build output are touched
- - if: '$QEMU_CI == "1" && $CI_PROJECT_NAMESPACE != "qemu-project"'
- changes:
- - .gitlab-ci.d/opensbi.yml
- - .gitlab-ci.d/opensbi/Dockerfile
- - roms/opensbi/*
- when: manual
-
- # In forks, if QEMU_CI=1 is set, then create manual job
- # if the branch/tag starts with 'opensbi'
- - if: '$QEMU_CI == "1" && $CI_PROJECT_NAMESPACE != "qemu-project" && $CI_COMMIT_REF_NAME =~ /^opensbi/'
- when: manual
-
- # In forks, if QEMU_CI=1 is set, then create manual job
- # if the last commit msg contains 'OpenSBI' (case insensitive)
- - if: '$QEMU_CI == "1" && $CI_PROJECT_NAMESPACE != "qemu-project" && $CI_COMMIT_MESSAGE =~ /opensbi/i'
- when: manual
-
- # Scheduled runs on mainline don't get pipelines except for the special Coverity job
- - if: '$CI_PROJECT_NAMESPACE == $QEMU_CI_UPSTREAM && $CI_PIPELINE_SOURCE == "schedule"'
- when: never
-
- # Run if any files affecting the build output are touched
- - changes:
- - .gitlab-ci.d/opensbi.yml
- - .gitlab-ci.d/opensbi/Dockerfile
- - roms/opensbi/*
- when: on_success
-
- # Run if the branch/tag starts with 'opensbi'
- - if: '$CI_COMMIT_REF_NAME =~ /^opensbi/'
- when: on_success
-
- # Run if the last commit msg contains 'OpenSBI' (case insensitive)
- - if: '$CI_COMMIT_MESSAGE =~ /opensbi/i'
- when: on_success
-
-docker-opensbi:
- extends: .opensbi_job_rules
- stage: containers
- image: docker:latest
- services:
- - docker:dind
- variables:
- GIT_DEPTH: 3
- IMAGE_TAG: $CI_REGISTRY_IMAGE:opensbi-cross-build
- before_script:
- - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY
- - until docker info; do sleep 1; done
- script:
- - docker pull $IMAGE_TAG || true
- - docker build --cache-from $IMAGE_TAG --tag $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
- --tag $IMAGE_TAG .gitlab-ci.d/opensbi
- - docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
- - docker push $IMAGE_TAG
-
-build-opensbi:
- extends: .opensbi_job_rules
- stage: build
- needs: ['docker-opensbi']
- artifacts:
- when: on_success
- paths: # 'artifacts.zip' will contains the following files:
- - pc-bios/opensbi-riscv32-generic-fw_dynamic.bin
- - pc-bios/opensbi-riscv64-generic-fw_dynamic.bin
- - opensbi32-generic-stdout.log
- - opensbi32-generic-stderr.log
- - opensbi64-generic-stdout.log
- - opensbi64-generic-stderr.log
- image: $CI_REGISTRY_IMAGE:opensbi-cross-build
- variables:
- GIT_DEPTH: 3
- script: # Clone the required submodules and build OpenSBI
- - git submodule update --init roms/opensbi
- - export JOBS=$(($(getconf _NPROCESSORS_ONLN) + 1))
- - echo "=== Using ${JOBS} simultaneous jobs ==="
- - make -j${JOBS} -C roms/opensbi clean
- - make -j${JOBS} -C roms opensbi32-generic 2>&1 1>opensbi32-generic-stdout.log | tee -a opensbi32-generic-stderr.log >&2
- - make -j${JOBS} -C roms/opensbi clean
- - make -j${JOBS} -C roms opensbi64-generic 2>&1 1>opensbi64-generic-stdout.log | tee -a opensbi64-generic-stderr.log >&2
diff --git a/.gitlab-ci.d/opensbi/Dockerfile b/.gitlab-ci.d/opensbi/Dockerfile
deleted file mode 100644
index 5ccf4151f4..0000000000
--- a/.gitlab-ci.d/opensbi/Dockerfile
+++ /dev/null
@@ -1,34 +0,0 @@
-#
-# Docker image to cross-compile OpenSBI firmware binaries
-#
-FROM ubuntu:18.04
-
-MAINTAINER Bin Meng <bmeng.cn@gmail.com>
-
-# Install packages required to build OpenSBI
-RUN apt update \
- && \
- \
- DEBIAN_FRONTEND=noninteractive \
- apt install --assume-yes --no-install-recommends \
- build-essential \
- ca-certificates \
- git \
- make \
- python3 \
- wget \
- && \
- \
- rm -rf /var/lib/apt/lists/*
-
-# Manually install the kernel.org "Crosstool" based toolchains for gcc-8.3
-RUN wget -O - \
- https://mirrors.edge.kernel.org/pub/tools/crosstool/files/bin/x86_64/8.3.0/x86_64-gcc-8.3.0-nolibc-riscv32-linux.tar.xz \
- | tar -C /opt -xJ
-RUN wget -O - \
- https://mirrors.edge.kernel.org/pub/tools/crosstool/files/bin/x86_64/8.3.0/x86_64-gcc-8.3.0-nolibc-riscv64-linux.tar.xz \
- | tar -C /opt -xJ
-
-# Export the toolchains to the system path
-ENV PATH="/opt/gcc-8.3.0-nolibc/riscv32-linux/bin:${PATH}"
-ENV PATH="/opt/gcc-8.3.0-nolibc/riscv64-linux/bin:${PATH}"
diff --git a/.gitlab-ci.d/qemu-project.yml b/.gitlab-ci.d/qemu-project.yml
index 104a147b2d..72d02bc65b 100644
--- a/.gitlab-ci.d/qemu-project.yml
+++ b/.gitlab-ci.d/qemu-project.yml
@@ -11,7 +11,6 @@ default:
include:
- local: '/.gitlab-ci.d/base.yml'
- local: '/.gitlab-ci.d/stages.yml'
- - local: '/.gitlab-ci.d/opensbi.yml'
- local: '/.gitlab-ci.d/containers.yml'
- local: '/.gitlab-ci.d/crossbuilds.yml'
- local: '/.gitlab-ci.d/buildtest.yml'
--
2.34.1
On Tue, Jul 7, 2026 at 2:23 AM Bin Meng <bin.meng@processmission.com> wrote:
>
> The OpenSBI firmware build job follows the same pattern as the EDK2 job
> [1] that was removed earlier [2]: it exists to produce firmware binaries
> from CI artifacts, but those outputs are not consumed by the tree.
>
> Remove the job definition and its project include to avoid maintaining
> bitrotting container and firmware build logic.
>
> [1] 71920809ceab ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries")
> [2] 690ceb71936f ("gitlab-ci: Remove job building EDK2 firmware binaries")
>
> Signed-off-by: Bin Meng <bin.meng@processmission.com>
Thanks!
Applied to riscv-to-apply.next
Alistair
>
> ---
>
> MAINTAINERS | 2 -
> .gitlab-ci.d/opensbi.yml | 88 ---------------------------------
> .gitlab-ci.d/opensbi/Dockerfile | 34 -------------
> .gitlab-ci.d/qemu-project.yml | 1 -
> 4 files changed, 125 deletions(-)
> delete mode 100644 .gitlab-ci.d/opensbi.yml
> delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
>
> diff --git a/MAINTAINERS b/MAINTAINERS
> index 97dcc78ded..59707bf2a7 100644
> --- a/MAINTAINERS
> +++ b/MAINTAINERS
> @@ -4117,8 +4117,6 @@ R: Daniel Henrique Barboza <daniel.barboza@oss.qualcomm.com>
> L: qemu-riscv@nongnu.org
> S: Supported
> F: pc-bios/opensbi-*
> -F: .gitlab-ci.d/opensbi.yml
> -F: .gitlab-ci.d/opensbi/
>
> Clock framework
> M: Luc Michel <luc@lmichel.fr>
> diff --git a/.gitlab-ci.d/opensbi.yml b/.gitlab-ci.d/opensbi.yml
> deleted file mode 100644
> index 42f137d624..0000000000
> --- a/.gitlab-ci.d/opensbi.yml
> +++ /dev/null
> @@ -1,88 +0,0 @@
> -# All jobs needing docker-opensbi must use the same rules it uses.
> -.opensbi_job_rules:
> - rules:
> - # Forks don't get pipelines unless QEMU_CI=1 or QEMU_CI=2 is set
> - - if: '$QEMU_CI != "1" && $QEMU_CI != "2" && $CI_PROJECT_NAMESPACE != "qemu-project"'
> - when: never
> -
> - # In forks, if QEMU_CI=1 is set, then create manual job
> - # if any files affecting the build output are touched
> - - if: '$QEMU_CI == "1" && $CI_PROJECT_NAMESPACE != "qemu-project"'
> - changes:
> - - .gitlab-ci.d/opensbi.yml
> - - .gitlab-ci.d/opensbi/Dockerfile
> - - roms/opensbi/*
> - when: manual
> -
> - # In forks, if QEMU_CI=1 is set, then create manual job
> - # if the branch/tag starts with 'opensbi'
> - - if: '$QEMU_CI == "1" && $CI_PROJECT_NAMESPACE != "qemu-project" && $CI_COMMIT_REF_NAME =~ /^opensbi/'
> - when: manual
> -
> - # In forks, if QEMU_CI=1 is set, then create manual job
> - # if the last commit msg contains 'OpenSBI' (case insensitive)
> - - if: '$QEMU_CI == "1" && $CI_PROJECT_NAMESPACE != "qemu-project" && $CI_COMMIT_MESSAGE =~ /opensbi/i'
> - when: manual
> -
> - # Scheduled runs on mainline don't get pipelines except for the special Coverity job
> - - if: '$CI_PROJECT_NAMESPACE == $QEMU_CI_UPSTREAM && $CI_PIPELINE_SOURCE == "schedule"'
> - when: never
> -
> - # Run if any files affecting the build output are touched
> - - changes:
> - - .gitlab-ci.d/opensbi.yml
> - - .gitlab-ci.d/opensbi/Dockerfile
> - - roms/opensbi/*
> - when: on_success
> -
> - # Run if the branch/tag starts with 'opensbi'
> - - if: '$CI_COMMIT_REF_NAME =~ /^opensbi/'
> - when: on_success
> -
> - # Run if the last commit msg contains 'OpenSBI' (case insensitive)
> - - if: '$CI_COMMIT_MESSAGE =~ /opensbi/i'
> - when: on_success
> -
> -docker-opensbi:
> - extends: .opensbi_job_rules
> - stage: containers
> - image: docker:latest
> - services:
> - - docker:dind
> - variables:
> - GIT_DEPTH: 3
> - IMAGE_TAG: $CI_REGISTRY_IMAGE:opensbi-cross-build
> - before_script:
> - - docker login -u $CI_REGISTRY_USER -p $CI_REGISTRY_PASSWORD $CI_REGISTRY
> - - until docker info; do sleep 1; done
> - script:
> - - docker pull $IMAGE_TAG || true
> - - docker build --cache-from $IMAGE_TAG --tag $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
> - --tag $IMAGE_TAG .gitlab-ci.d/opensbi
> - - docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
> - - docker push $IMAGE_TAG
> -
> -build-opensbi:
> - extends: .opensbi_job_rules
> - stage: build
> - needs: ['docker-opensbi']
> - artifacts:
> - when: on_success
> - paths: # 'artifacts.zip' will contains the following files:
> - - pc-bios/opensbi-riscv32-generic-fw_dynamic.bin
> - - pc-bios/opensbi-riscv64-generic-fw_dynamic.bin
> - - opensbi32-generic-stdout.log
> - - opensbi32-generic-stderr.log
> - - opensbi64-generic-stdout.log
> - - opensbi64-generic-stderr.log
> - image: $CI_REGISTRY_IMAGE:opensbi-cross-build
> - variables:
> - GIT_DEPTH: 3
> - script: # Clone the required submodules and build OpenSBI
> - - git submodule update --init roms/opensbi
> - - export JOBS=$(($(getconf _NPROCESSORS_ONLN) + 1))
> - - echo "=== Using ${JOBS} simultaneous jobs ==="
> - - make -j${JOBS} -C roms/opensbi clean
> - - make -j${JOBS} -C roms opensbi32-generic 2>&1 1>opensbi32-generic-stdout.log | tee -a opensbi32-generic-stderr.log >&2
> - - make -j${JOBS} -C roms/opensbi clean
> - - make -j${JOBS} -C roms opensbi64-generic 2>&1 1>opensbi64-generic-stdout.log | tee -a opensbi64-generic-stderr.log >&2
> diff --git a/.gitlab-ci.d/opensbi/Dockerfile b/.gitlab-ci.d/opensbi/Dockerfile
> deleted file mode 100644
> index 5ccf4151f4..0000000000
> --- a/.gitlab-ci.d/opensbi/Dockerfile
> +++ /dev/null
> @@ -1,34 +0,0 @@
> -#
> -# Docker image to cross-compile OpenSBI firmware binaries
> -#
> -FROM ubuntu:18.04
> -
> -MAINTAINER Bin Meng <bmeng.cn@gmail.com>
> -
> -# Install packages required to build OpenSBI
> -RUN apt update \
> - && \
> - \
> - DEBIAN_FRONTEND=noninteractive \
> - apt install --assume-yes --no-install-recommends \
> - build-essential \
> - ca-certificates \
> - git \
> - make \
> - python3 \
> - wget \
> - && \
> - \
> - rm -rf /var/lib/apt/lists/*
> -
> -# Manually install the kernel.org "Crosstool" based toolchains for gcc-8.3
> -RUN wget -O - \
> - https://mirrors.edge.kernel.org/pub/tools/crosstool/files/bin/x86_64/8.3.0/x86_64-gcc-8.3.0-nolibc-riscv32-linux.tar.xz \
> - | tar -C /opt -xJ
> -RUN wget -O - \
> - https://mirrors.edge.kernel.org/pub/tools/crosstool/files/bin/x86_64/8.3.0/x86_64-gcc-8.3.0-nolibc-riscv64-linux.tar.xz \
> - | tar -C /opt -xJ
> -
> -# Export the toolchains to the system path
> -ENV PATH="/opt/gcc-8.3.0-nolibc/riscv32-linux/bin:${PATH}"
> -ENV PATH="/opt/gcc-8.3.0-nolibc/riscv64-linux/bin:${PATH}"
> diff --git a/.gitlab-ci.d/qemu-project.yml b/.gitlab-ci.d/qemu-project.yml
> index 104a147b2d..72d02bc65b 100644
> --- a/.gitlab-ci.d/qemu-project.yml
> +++ b/.gitlab-ci.d/qemu-project.yml
> @@ -11,7 +11,6 @@ default:
> include:
> - local: '/.gitlab-ci.d/base.yml'
> - local: '/.gitlab-ci.d/stages.yml'
> - - local: '/.gitlab-ci.d/opensbi.yml'
> - local: '/.gitlab-ci.d/containers.yml'
> - local: '/.gitlab-ci.d/crossbuilds.yml'
> - local: '/.gitlab-ci.d/buildtest.yml'
> --
> 2.34.1
>
>
On 7/6/2026 9:17 AM, Bin Meng wrote:
> The OpenSBI firmware build job follows the same pattern as the EDK2 job
> [1] that was removed earlier [2]: it exists to produce firmware binaries
> from CI artifacts, but those outputs are not consumed by the tree.
>
> Remove the job definition and its project include to avoid maintaining
> bitrotting container and firmware build logic.
>
> [1] 71920809ceab ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries")
> [2] 690ceb71936f ("gitlab-ci: Remove job building EDK2 firmware binaries")
>
> Signed-off-by: Bin Meng <bin.meng@processmission.com>
>
> ---
>
> MAINTAINERS | 2 -
> .gitlab-ci.d/opensbi.yml | 88 ---------------------------------
> .gitlab-ci.d/opensbi/Dockerfile | 34 -------------
> .gitlab-ci.d/qemu-project.yml | 1 -
> 4 files changed, 125 deletions(-)
> delete mode 100644 .gitlab-ci.d/opensbi.yml
> delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
>
All good on my side, but let's check with official maintainer and
reviewer for this file to make sure it's ok.
@Alistair, @Daniel, are you ok with this removal?
Regards,
Pierrick
On 7/6/2026 6:08 PM, Pierrick Bouvier wrote:
> On 7/6/2026 9:17 AM, Bin Meng wrote:
>> The OpenSBI firmware build job follows the same pattern as the EDK2 job
>> [1] that was removed earlier [2]: it exists to produce firmware binaries
>> from CI artifacts, but those outputs are not consumed by the tree.
>>
>> Remove the job definition and its project include to avoid maintaining
>> bitrotting container and firmware build logic.
>>
>> [1] 71920809ceab ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries")
>> [2] 690ceb71936f ("gitlab-ci: Remove job building EDK2 firmware binaries")
>>
>> Signed-off-by: Bin Meng <bin.meng@processmission.com>
>>
>> ---
>>
>> MAINTAINERS | 2 -
>> .gitlab-ci.d/opensbi.yml | 88 ---------------------------------
>> .gitlab-ci.d/opensbi/Dockerfile | 34 -------------
>> .gitlab-ci.d/qemu-project.yml | 1 -
>> 4 files changed, 125 deletions(-)
>> delete mode 100644 .gitlab-ci.d/opensbi.yml
>> delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
>>
>
> All good on my side, but let's check with official maintainer and
> reviewer for this file to make sure it's ok.
>
> @Alistair, @Daniel, are you ok with this removal?
Checking the git log for opensbi.yml this is the most recent commit:
commit 83aa1baa069c8f77aa9f7d9adfdeb11d90bdf78d
Author: Paolo Bonzini <pbonzini@redhat.com>
Date: Mon Mar 4 13:16:50 2024 -0500
gitlab-ci: add manual job to run Coverity
Add a job that can be run, either manually or on a schedule, to upload
a build to Coverity Scan. The job uses the run-coverity-scan script
in multiple phases of check, download tools and upload, in order to
avoid both wasting time (skip everything if you are above the upload
quota) and avoid filling the log with the progress of downloading
the tools.
The job is intended to run on a scheduled pipeline run, and scheduled
runs will not get any other job. It requires two variables to be in
GitLab CI, COVERITY_TOKEN and COVERITY_EMAIL. Those are already set up
in qemu-project's configuration as protected and masked variables.
I'm not sure what's the actual impact of removing the OpenSBI job would have with
this Coverity usage. Maybe we don't really care about Coverity downloading and using
opensbi for whatever Coverity must do and we can remove the job anyway. I would like
to hear from Alistair and the others about the possible impact first though.
Also, this opensbi job has been around since 2020 and Phil's commit that removed
the EDK2 job is dated 2023. I'd think that Phil would remove this opensbi job along
the EDK2 job if the criteria was the same, and yet this job is still here. Maybe
there's some lore behind it ... Phil, do you remember this stuff?
Thanks,
Daniel
>
> Regards,
> Pierrick
On Tue, Jul 7, 2026 at 11:08 AM Daniel Henrique Barboza
<daniel.barboza@oss.qualcomm.com> wrote:
>
>
>
> On 7/6/2026 6:08 PM, Pierrick Bouvier wrote:
> > On 7/6/2026 9:17 AM, Bin Meng wrote:
> >> The OpenSBI firmware build job follows the same pattern as the EDK2 job
> >> [1] that was removed earlier [2]: it exists to produce firmware binaries
> >> from CI artifacts, but those outputs are not consumed by the tree.
> >>
> >> Remove the job definition and its project include to avoid maintaining
> >> bitrotting container and firmware build logic.
> >>
> >> [1] 71920809ceab ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries")
> >> [2] 690ceb71936f ("gitlab-ci: Remove job building EDK2 firmware binaries")
> >>
> >> Signed-off-by: Bin Meng <bin.meng@processmission.com>
> >>
> >> ---
> >>
> >> MAINTAINERS | 2 -
> >> .gitlab-ci.d/opensbi.yml | 88 ---------------------------------
> >> .gitlab-ci.d/opensbi/Dockerfile | 34 -------------
> >> .gitlab-ci.d/qemu-project.yml | 1 -
> >> 4 files changed, 125 deletions(-)
> >> delete mode 100644 .gitlab-ci.d/opensbi.yml
> >> delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
> >>
> >
> > All good on my side, but let's check with official maintainer and
> > reviewer for this file to make sure it's ok.
> >
> > @Alistair, @Daniel, are you ok with this removal?
>
> Checking the git log for opensbi.yml this is the most recent commit:
>
> commit 83aa1baa069c8f77aa9f7d9adfdeb11d90bdf78d
> Author: Paolo Bonzini <pbonzini@redhat.com>
> Date: Mon Mar 4 13:16:50 2024 -0500
>
> gitlab-ci: add manual job to run Coverity
>
> Add a job that can be run, either manually or on a schedule, to upload
> a build to Coverity Scan. The job uses the run-coverity-scan script
> in multiple phases of check, download tools and upload, in order to
> avoid both wasting time (skip everything if you are above the upload
> quota) and avoid filling the log with the progress of downloading
> the tools.
>
> The job is intended to run on a scheduled pipeline run, and scheduled
> runs will not get any other job. It requires two variables to be in
> GitLab CI, COVERITY_TOKEN and COVERITY_EMAIL. Those are already set up
> in qemu-project's configuration as protected and masked variables.
>
>
> I'm not sure what's the actual impact of removing the OpenSBI job would have with
> this Coverity usage. Maybe we don't really care about Coverity downloading and using
> opensbi for whatever Coverity must do and we can remove the job anyway. I would like
> to hear from Alistair and the others about the possible impact first though.
I don't have any insight. I didn't even realise we were doing this as
part of the CI.
>
>
> Also, this opensbi job has been around since 2020 and Phil's commit that removed
> the EDK2 job is dated 2023. I'd think that Phil would remove this opensbi job along
> the EDK2 job if the criteria was the same, and yet this job is still here. Maybe
> there's some lore behind it ... Phil, do you remember this stuff?
Phil reviewed this change, and the commit that removed EDK2 support says:
commit 690ceb71936f9037f6e11580709e26b62d83c17c
Author: Philippe Mathieu-Daudé <philmd@mailo.com>
Date: Fri Mar 10 14:32:47 2023 +0100
gitlab-ci: Remove job building EDK2 firmware binaries
When we introduced this Gitlab-CI job in commit 71920809ce
("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries"),
the naive plan was to have reproducible binaries by downloading
what this job would build, testing it and eventually committing
it. With retrospective, nothing happened 3 years later and this
job is just bitrotting:
So I think we are ok to remove this:
Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
Alistair
On 9/7/26 07:07, Alistair Francis wrote:
> On Tue, Jul 7, 2026 at 11:08 AM Daniel Henrique Barboza
> <daniel.barboza@oss.qualcomm.com> wrote:
>>
>>
>>
>> On 7/6/2026 6:08 PM, Pierrick Bouvier wrote:
>>> On 7/6/2026 9:17 AM, Bin Meng wrote:
>>>> The OpenSBI firmware build job follows the same pattern as the EDK2 job
>>>> [1] that was removed earlier [2]: it exists to produce firmware binaries
>>>> from CI artifacts, but those outputs are not consumed by the tree.
>>>>
>>>> Remove the job definition and its project include to avoid maintaining
>>>> bitrotting container and firmware build logic.
>>>>
>>>> [1] 71920809ceab ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries")
>>>> [2] 690ceb71936f ("gitlab-ci: Remove job building EDK2 firmware binaries")
>>>>
>>>> Signed-off-by: Bin Meng <bin.meng@processmission.com>
>>>>
>>>> ---
>>>>
>>>> MAINTAINERS | 2 -
>>>> .gitlab-ci.d/opensbi.yml | 88 ---------------------------------
>>>> .gitlab-ci.d/opensbi/Dockerfile | 34 -------------
>>>> .gitlab-ci.d/qemu-project.yml | 1 -
>>>> 4 files changed, 125 deletions(-)
>>>> delete mode 100644 .gitlab-ci.d/opensbi.yml
>>>> delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
>>>>
>>>
>>> All good on my side, but let's check with official maintainer and
>>> reviewer for this file to make sure it's ok.
>>>
>>> @Alistair, @Daniel, are you ok with this removal?
>>
>> Checking the git log for opensbi.yml this is the most recent commit:
>>
>> commit 83aa1baa069c8f77aa9f7d9adfdeb11d90bdf78d
>> Author: Paolo Bonzini <pbonzini@redhat.com>
>> Date: Mon Mar 4 13:16:50 2024 -0500
>>
>> gitlab-ci: add manual job to run Coverity
>>
>> Add a job that can be run, either manually or on a schedule, to upload
>> a build to Coverity Scan. The job uses the run-coverity-scan script
>> in multiple phases of check, download tools and upload, in order to
>> avoid both wasting time (skip everything if you are above the upload
>> quota) and avoid filling the log with the progress of downloading
>> the tools.
>>
>> The job is intended to run on a scheduled pipeline run, and scheduled
>> runs will not get any other job. It requires two variables to be in
>> GitLab CI, COVERITY_TOKEN and COVERITY_EMAIL. Those are already set up
>> in qemu-project's configuration as protected and masked variables.
>>
>>
>> I'm not sure what's the actual impact of removing the OpenSBI job would have with
>> this Coverity usage. Maybe we don't really care about Coverity downloading and using
>> opensbi for whatever Coverity must do and we can remove the job anyway. I would like
>> to hear from Alistair and the others about the possible impact first though.
>
> I don't have any insight. I didn't even realise we were doing this as
> part of the CI.
>
>>
>>
>> Also, this opensbi job has been around since 2020 and Phil's commit that removed
>> the EDK2 job is dated 2023. I'd think that Phil would remove this opensbi job along
>> the EDK2 job if the criteria was the same, and yet this job is still here. Maybe
>> there's some lore behind it ... Phil, do you remember this stuff?
>
> Phil reviewed this change, and the commit that removed EDK2 support says:
>
> commit 690ceb71936f9037f6e11580709e26b62d83c17c
> Author: Philippe Mathieu-Daudé <philmd@mailo.com>
> Date: Fri Mar 10 14:32:47 2023 +0100
>
> gitlab-ci: Remove job building EDK2 firmware binaries
>
> When we introduced this Gitlab-CI job in commit 71920809ce
> ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries"),
> the naive plan was to have reproducible binaries by downloading
> what this job would build, testing it and eventually committing
> it. With retrospective, nothing happened 3 years later and this
> job is just bitrotting:
>
>
> So I think we are ok to remove this:
Yes, thanks you!
>
> Reviewed-by: Alistair Francis <alistair.francis@wdc.com>
>
> Alistair
>
On 6/7/26 18:17, Bin Meng wrote:
> The OpenSBI firmware build job follows the same pattern as the EDK2 job
> [1] that was removed earlier [2]: it exists to produce firmware binaries
> from CI artifacts, but those outputs are not consumed by the tree.
>
> Remove the job definition and its project include to avoid maintaining
> bitrotting container and firmware build logic.
>
> [1] 71920809ceab ("gitlab-ci.yml: Add jobs to build EDK2 firmware binaries")
> [2] 690ceb71936f ("gitlab-ci: Remove job building EDK2 firmware binaries")
>
> Signed-off-by: Bin Meng <bin.meng@processmission.com>
>
> ---
>
> MAINTAINERS | 2 -
> .gitlab-ci.d/opensbi.yml | 88 ---------------------------------
> .gitlab-ci.d/opensbi/Dockerfile | 34 -------------
> .gitlab-ci.d/qemu-project.yml | 1 -
> 4 files changed, 125 deletions(-)
> delete mode 100644 .gitlab-ci.d/opensbi.yml
> delete mode 100644 .gitlab-ci.d/opensbi/Dockerfile
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
© 2016 - 2026 Red Hat, Inc.