summaryrefslogtreecommitdiff
path: root/scripts/package-build/linux-kernel/README.md
diff options
context:
space:
mode:
authorChristian Breunig <christian@breunig.cc>2026-10-01 20:59:10 +0200
committerGitHub <noreply@github.com>2026-10-01 20:59:10 +0200
commitf53ea3c722373c9469bb4c7ef542437af190956c (patch)
tree77f18f17b72d62633741504ae699c9d8f4fd10fc /scripts/package-build/linux-kernel/README.md
parent1bd13c5e9a07855aa869ef7f85357d84532d8dc0 (diff)
parent008bd51ac0ae70e24f13d602d96bce41a6220f89 (diff)
downloadvyos-build-f53ea3c722373c9469bb4c7ef542437af190956c.tar.gz
vyos-build-f53ea3c722373c9469bb4c7ef542437af190956c.zip
Merge pull request #1314 from c-po/T9014-kernel-config-refresh
Kernel: T9014: regenerate arm64 base config against Linux 6.18
Diffstat (limited to 'scripts/package-build/linux-kernel/README.md')
-rw-r--r--scripts/package-build/linux-kernel/README.md65
1 files changed, 56 insertions, 9 deletions
diff --git a/scripts/package-build/linux-kernel/README.md b/scripts/package-build/linux-kernel/README.md
index cc02262a..56ef649b 100644
--- a/scripts/package-build/linux-kernel/README.md
+++ b/scripts/package-build/linux-kernel/README.md
@@ -5,9 +5,10 @@
# About
-VyOS runs on a custom Linux Kernel (which is 6.6) at the time of this writing.
-This repository holds build scripts that are used to build the Custom Kernel
-(x86_64/amd64 at the moment) and all required out-of tree modules.
+VyOS runs on a custom Linux Kernel. The version built is pinned by
+`kernel_version` in [data/defaults.toml](../../../data/defaults.toml). This
+repository holds the build scripts used to build the custom Kernel for
+x86_64/amd64 and arm64, plus all required out-of-tree modules.
VyOS does not utilize the build in Intel Kernel drivers for its NICs as those
Kernels sometimes lack features e.g. configurable receive-side-scaling queues.
@@ -16,16 +17,62 @@ On the other hand we ship additional not mainlined features as WireGuard VPN.
## Kernel
The Kernel is build from the vanilla repositories hosted at https://git.kernel.org.
-VyOS requires two additional patches to work which are stored in the patches/kernel
-folder.
+VyOS requires a few additional patches to work which are stored in the
+patches/kernel folder. They are applied *before* the Kernel configuration is
+generated, as a patch may introduce new Kconfig symbols.
### Config
-The Kernel configuration used is [x86_64_vyos_defconfig](x86_64_vyos_defconfig)
-which will be copied on demand during the Pipeline run into the `arch/x86/configs`
-directory of the Kernel source tree.
+The Kernel configuration is assembled by `build-kernel.sh` using the Kernel's own
+`scripts/kconfig/merge_config.sh`:
-Other configurations can be added in the future easily.
+* a per-architecture base configuration, selected from `dpkg --print-architecture`
+ * amd64 -> [config/x86/vyos_defconfig](config/x86/vyos_defconfig)
+ * arm64 -> [config/arm64/vyos_defconfig](config/arm64/vyos_defconfig)
+* all feature snippets in [config/](config/) (`config/*.config`), merged on top of
+ the base in file name order
+* a temporary snippet enabling module signing, generated at build time when
+ `data/certificates/*.pem` are present
+
+`merge_config.sh` concatenates all of the above, runs `make alldefconfig`, and
+then verifies that every requested line appears verbatim in the resulting
+`.config`. Any that does not is reported as:
+
+```
+Value requested for CONFIG_FOO not in final .config
+```
+
+These warnings are deliberately **not** suppressed - they are the only signal we
+get when a snippet silently stops taking effect (symbol removed upstream,
+dependency no longer met, or a value overridden by a `select`). Treat a new
+warning as a bug to be investigated, not as noise.
+
+#### Regenerating a base configuration
+
+The per-architecture base configurations are full `.config` dumps and must be
+regenerated whenever they fall far enough behind the Kernel version that the
+warnings above become unmanageable. Build natively on the target architecture
+and run:
+
+```bash
+cd scripts/package-build/linux-kernel/linux
+scripts/kconfig/merge_config.sh ../config/<arch>/vyos_defconfig ../config/*.config
+cd ..
+cp linux/.config config/<arch>/vyos_defconfig
+# host specific values - these differ per builder and must never be committed
+sed -i -E '/^CONFIG_(CC_VERSION_TEXT|GCC_VERSION|CLANG_VERSION|LLD_VERSION|RUSTC_VERSION|RUSTC_LLVM_VERSION|AS_VERSION|LD_VERSION|PAHOLE_VERSION)=/d' config/<arch>/vyos_defconfig
+# injected at build time from data/certificates - must never be committed
+sed -i -E '/^CONFIG_SYSTEM_TRUSTED_KEYS=/d' config/<arch>/vyos_defconfig
+```
+
+Re-running `merge_config.sh` against the regenerated file must now produce a
+byte identical `.config` - that fixed point is the proof the file is canonical.
+Verify there is no functional change by diffing the produced `.config` from
+before and after, never the `vyos_defconfig` files themselves.
+
+Note that `build-kernel.sh` starts with `git reset --hard` and `git clean -fdx`
+inside `linux/`, so anything you want to keep from a previous run has to be
+copied out of that directory first.
### Modules