Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 4 additions & 14 deletions .github/workflows/_test_cadence.yml
Original file line number Diff line number Diff line change
@@ -1,17 +1,15 @@
name: Test Cadence

permissions:
id-token: write
contents: read

on:
workflow_call:
inputs:
docker-image:
description: 'Name of the docker image to use, without registry or tag suffix'
required: false
description: 'Fully qualified CI image (resolved by the caller)'
required: true
type: string
default: ci-image:executorch-ubuntu-22.04-clang12
runner:
description: 'Runner type'
required: false
Expand All @@ -29,20 +27,14 @@ on:
default: 90

jobs:
docker-image:
name: Resolve CI docker image
uses: ./.github/workflows/_docker-image.yml

test-aot:
needs: docker-image
uses: pytorch/test-infra/.github/workflows/linux_job_v3.yml@main
permissions:
id-token: write
contents: read
with:
job-name: test-aot
runner: ${{ inputs.runner }}
docker-image: ${{ needs.docker-image.outputs.docker-registry }}/${{ inputs.docker-image }}-${{ needs.docker-image.outputs.ci-docker-hash }}
docker-image: ${{ inputs.docker-image }}
submodules: recursive
ref: ${{ inputs.ref }}
timeout: ${{ inputs.timeout }}
Expand All @@ -58,15 +50,13 @@ jobs:
python -m pytest backends/cadence/aot/tests/ -v -n auto --reruns 2 --reruns-delay 1

test-ops:
needs: docker-image
uses: pytorch/test-infra/.github/workflows/linux_job_v3.yml@main
permissions:
id-token: write
contents: read
with:
job-name: test-ops
runner: ${{ inputs.runner }}
docker-image: ${{ needs.docker-image.outputs.docker-registry }}/${{ inputs.docker-image }}-${{ needs.docker-image.outputs.ci-docker-hash }}
docker-image: ${{ inputs.docker-image }}
submodules: recursive
ref: ${{ inputs.ref }}
timeout: ${{ inputs.timeout }}
Expand Down
32 changes: 19 additions & 13 deletions .github/workflows/_xtensa_build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,25 +20,28 @@ on:
required: false
type: string
default: ""
docker-image:
description: "Fully qualified CI image (resolved by the caller)"
required: true
type: string
allow-fork-checkout:
description: "Check out fork PR code on pull_request_target"
required: false
type: boolean
default: false

jobs:
# The runner pod pulls the container before any step runs, so the image has to
# be a fully qualified reference resolved by a job this one depends on.
docker-image:
name: Resolve CI docker image
uses: ./.github/workflows/_docker-image.yml

build:
name: ${{ inputs.backend }}
needs: docker-image
# Intel, not the x86iavx512 (r7a/AMD) default: the Cadence licence key that
# xt-clang computes for a core differs by CPU vendor, and only the Intel one
# (XT_XCC_TIE_ED4D1230) is in the bundled licence. On an AMD runner the
# vision core resolves to XT_XCC_TIE_ED4DB539 and the checkout fails with
# "No such feature exists". hifi4's older RI-2022.10 toolchain does not care.
# Keep this label at 18 characters or fewer. The pod hostname is the label plus
# 28 characters, and RJ-2025.5 xt-clang (vision) derives the wrong licence key
# once the hostname reaches 47: it asks for XT_XCC_TIE_ED4DB539 instead of the
# bundled ED4D1230 and fails with "No such feature exists". The CPU vendor is
# not the cause; mt-l-x86iavx512-8-64 (20 characters) fails on its hostname.
# hifi4's RI-2022.9 toolchain is unaffected.
runs-on: mt-l-x86iamx-8-64
container:
image: ${{ needs.docker-image.outputs.docker-registry }}/ci-image:executorch-ubuntu-22.04-clang12-${{ needs.docker-image.outputs.ci-docker-hash }}
image: ${{ inputs.docker-image }}
environment: cadence
permissions:
id-token: write
Expand All @@ -63,6 +66,8 @@ jobs:
with:
submodules: recursive
ref: ${{ inputs.ref }}
persist-credentials: ${{ !inputs.allow-fork-checkout }}
allow-unsafe-pr-checkout: ${{ inputs.allow-fork-checkout }}

- name: Assume Cadence artifacts role
uses: aws-actions/configure-aws-credentials@v4
Expand Down Expand Up @@ -92,6 +97,7 @@ jobs:
chmod -R a+rX cmake-out

- name: Upload runner
if: ${{ !inputs.allow-fork-checkout }}
uses: actions/upload-artifact@v4
with:
name: cadence-xtensa-build-${{ inputs.backend }}
Expand Down
31 changes: 18 additions & 13 deletions .github/workflows/_xtensa_test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,25 +19,28 @@ on:
required: false
type: string
default: ""
docker-image:
description: "Fully qualified CI image (resolved by the caller)"
required: true
type: string
allow-fork-checkout:
description: "Check out fork PR code on pull_request_target"
required: false
type: boolean
default: false

jobs:
# The runner pod pulls the container before any step runs, so the image has to
# be a fully qualified reference resolved by a job this one depends on.
docker-image:
name: Resolve CI docker image
uses: ./.github/workflows/_docker-image.yml

test:
name: ${{ inputs.backend }}
needs: docker-image
# Intel, not the x86iavx512 (r7a/AMD) default: the Cadence licence key that
# xt-clang computes for a core differs by CPU vendor, and only the Intel one
# (XT_XCC_TIE_ED4D1230) is in the bundled licence. On an AMD runner the
# vision core resolves to XT_XCC_TIE_ED4DB539 and the checkout fails with
# "No such feature exists". hifi4's older RI-2022.10 toolchain does not care.
# Keep this label at 18 characters or fewer. The pod hostname is the label plus
# 28 characters, and RJ-2025.5 xt-clang (vision) derives the wrong licence key
# once the hostname reaches 47: it asks for XT_XCC_TIE_ED4DB539 instead of the
# bundled ED4D1230 and fails with "No such feature exists". The CPU vendor is
# not the cause; mt-l-x86iavx512-8-64 (20 characters) fails on its hostname.
# hifi4's RI-2022.9 toolchain is unaffected.
runs-on: mt-l-x86iamx-8-64
container:
image: ${{ needs.docker-image.outputs.docker-registry }}/ci-image:executorch-ubuntu-22.04-clang12-${{ needs.docker-image.outputs.ci-docker-hash }}
image: ${{ inputs.docker-image }}
environment: cadence
permissions:
id-token: write
Expand All @@ -62,6 +65,8 @@ jobs:
with:
submodules: recursive
ref: ${{ inputs.ref }}
persist-credentials: ${{ !inputs.allow-fork-checkout }}
allow-unsafe-pr-checkout: ${{ inputs.allow-fork-checkout }}

- name: Assume Cadence artifacts role
uses: aws-actions/configure-aws-credentials@v4
Expand Down
79 changes: 61 additions & 18 deletions .github/workflows/build-cadence-runner.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,40 +10,75 @@ on:
tags:
- ciflow/nightly/*
pull_request:
# Fork PRs, Meta exports from personal forks included. pull_request_target
# always runs this file from the default branch, so the paths filter below only
# affects fork PRs.
pull_request_target:
types: [labeled]
types: [opened, synchronize, reopened]
paths:
- backends/cadence/**
- examples/cadence/**
- .ci/scripts/setup-xtensa-tools.sh
- .ci/scripts/build-cadence-xtensa.sh
- .ci/scripts/test-cadence-xtensa.sh
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.event_name }}-${{ github.event.pull_request.number || github.ref_name }}-${{ github.ref_type == 'branch' && github.sha }}
cancel-in-progress: true

# Every job runs on the same paths. Same-repo PRs use pull_request, which reads
# the PR's own workflow AND code -- so CI changes, new test jobs, code, and tests
# are all validated pre-merge. Fork PRs can't get credentials (OIDC) there, so
# fork PRs whose author has contributed before (CONTRIBUTOR or above) run on
# pull_request_target instead. The CPU jobs hold no AWS credentials on any path
# (contents: read only), so linux_job_v3's role/arc never reaches fork code; only
# the Xtensa jobs assume a role, the Cadence artifacts one. The run condition is
# inlined per job (GitHub Actions has no YAML anchors and env is unavailable in
# job-level if), so keep the copies in sync.
jobs:
# Resolves the image inline rather than through the shared _docker-image.yml,
# which checks out the PR head: actions/checkout refuses that for fork code on
# pull_request_target. There the image comes from the base branch (github.sha),
# which also keeps a fork from picking the image it runs in. Same-repo PRs read
# their own head, as _docker-image.yml does, so .ci/docker changes are tested.
docker-image:
name: Resolve CI docker image
uses: ./.github/workflows/_docker-image.yml
if: >-
github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' ||
(github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository) ||
(github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository &&
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.pull_request.author_association))
runs-on: ubuntu-latest
permissions:
contents: read
outputs:
image: ${{ steps.hash.outputs.image }}
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.head.sha || github.sha }}
persist-credentials: false
- id: hash
run: |
set -eu
CI_DOCKER_HASH="$(git rev-parse HEAD:.ci/docker)"
echo "image=308535385114.dkr.ecr.us-east-1.amazonaws.com/executorch/ci-image:executorch-ubuntu-22.04-clang12-${CI_DOCKER_HASH}" >> "$GITHUB_OUTPUT"

# Same-repo PRs run on pull_request, which reads the PR's own workflow AND code
# -- so CI changes, new test jobs, code, and tests are all validated pre-merge.
# Fork PRs can't get credentials (OIDC) on pull_request, so Meta-exported forks
# (labeled CLA Signed + meta-exported) run on pull_request_target instead. The
# run condition is inlined per job (GitHub Actions has no YAML anchors and env
# is unavailable in job-level if), so keep the copies in sync.
cpu-build:
needs: docker-image
if: >-
github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' ||
(github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository) ||
(github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository &&
contains(github.event.pull_request.labels.*.name, 'CLA Signed') && contains(github.event.pull_request.labels.*.name, 'meta-exported'))
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.pull_request.author_association))
uses: pytorch/test-infra/.github/workflows/linux_job_v3.yml@main
permissions:
id-token: write
contents: read
with:
job-name: build
runner: mt-l-x86iavx512-8-64
docker-image: ${{ needs.docker-image.outputs.docker-registry }}/ci-image:executorch-ubuntu-22.04-clang12-${{ needs.docker-image.outputs.ci-docker-hash }}
docker-image: ${{ needs.docker-image.outputs.image }}
submodules: recursive
ref: ${{ (github.event_name == 'pull_request' || github.event_name == 'pull_request_target') && github.event.pull_request.head.sha || github.sha }}
timeout: 90
Expand All @@ -61,66 +96,74 @@ jobs:
cp cmake-out/backends/cadence/cadence_runner "${RUNNER_ARTIFACT_DIR}/"

cpu-test:
needs: cpu-build
needs: [docker-image, cpu-build]
if: >-
github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' ||
(github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository) ||
(github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository &&
contains(github.event.pull_request.labels.*.name, 'CLA Signed') && contains(github.event.pull_request.labels.*.name, 'meta-exported'))
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.pull_request.author_association))
permissions:
id-token: write
contents: read
uses: ./.github/workflows/_test_cadence.yml
with:
docker-image: ${{ needs.docker-image.outputs.image }}
ref: ${{ (github.event_name == 'pull_request' || github.event_name == 'pull_request_target') && github.event.pull_request.head.sha || github.sha }}

# Cross-compile cadence_executor_runner for each Cadence Xtensa core, one job
# per backend so they show as separate lines (no matrix grouping). Shared logic
# lives in _xtensa_build.yml. fusion_g3 is omitted until the upstream fusion_g3
# <-> nnlib-FusionG3 API skew is fixed (its runner does not link).
hifi-build:
needs: docker-image
if: >-
github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' ||
(github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository) ||
(github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository &&
contains(github.event.pull_request.labels.*.name, 'CLA Signed') && contains(github.event.pull_request.labels.*.name, 'meta-exported'))
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.pull_request.author_association))
permissions:
id-token: write
contents: read
uses: ./.github/workflows/_xtensa_build.yml
with:
backend: hifi4
ref: ${{ (github.event_name == 'pull_request' || github.event_name == 'pull_request_target') && github.event.pull_request.head.sha || github.sha }}
docker-image: ${{ needs.docker-image.outputs.image }}
allow-fork-checkout: ${{ github.event_name == 'pull_request_target' }}

# Op-level gtest tests on the Xtensa ISS, mirroring cpu-build -> cpu-test. The
# op tests are a self-contained cross-compile (the gtests need exceptions and
# RTTI that the runner build disables), so this does not consume hifi-build's
# artifact; needs: hifi-build only to fail fast when the backend cannot build.
hifi-op-test:
needs: hifi-build
needs: [docker-image, hifi-build]
if: >-
github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' ||
(github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository) ||
(github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository &&
contains(github.event.pull_request.labels.*.name, 'CLA Signed') && contains(github.event.pull_request.labels.*.name, 'meta-exported'))
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.pull_request.author_association))
permissions:
id-token: write
contents: read
uses: ./.github/workflows/_xtensa_test.yml
with:
backend: hifi4
ref: ${{ (github.event_name == 'pull_request' || github.event_name == 'pull_request_target') && github.event.pull_request.head.sha || github.sha }}
docker-image: ${{ needs.docker-image.outputs.image }}
allow-fork-checkout: ${{ github.event_name == 'pull_request_target' }}

vision-build:
needs: docker-image
if: >-
github.event_name == 'push' || github.event_name == 'schedule' || github.event_name == 'workflow_dispatch' ||
(github.event_name == 'pull_request' && github.event.pull_request.head.repo.full_name == github.repository) ||
(github.event_name == 'pull_request_target' && github.event.pull_request.head.repo.full_name != github.repository &&
contains(github.event.pull_request.labels.*.name, 'CLA Signed') && contains(github.event.pull_request.labels.*.name, 'meta-exported'))
contains(fromJSON('["OWNER", "MEMBER", "COLLABORATOR", "CONTRIBUTOR"]'), github.event.pull_request.author_association))
permissions:
id-token: write
contents: read
uses: ./.github/workflows/_xtensa_build.yml
with:
backend: vision
ref: ${{ (github.event_name == 'pull_request' || github.event_name == 'pull_request_target') && github.event.pull_request.head.sha || github.sha }}
docker-image: ${{ needs.docker-image.outputs.image }}
allow-fork-checkout: ${{ github.event_name == 'pull_request_target' }}
Loading
Loading