Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1011 commits
Select commit Hold shift + click to select a range
81d9483
sysctl: set kernel.yama.ptrace_scope=2 to restrict ptrace access (#27…
xq9mend May 30, 2026
e38aa0e
Moved the Millenio gbsyncd docker to trixie (#26898)
govi-nokia May 30, 2026
0622d29
[submodule] Update submodule platform/vpp to the latest HEAD automati…
mssonicbld May 30, 2026
1b66c43
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld May 30, 2026
1c887a2
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld May 30, 2026
687f180
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld May 30, 2026
0e1b568
[submodule] Update submodule sonic-swss to the latest HEAD automatica…
mssonicbld May 30, 2026
78bd07c
[submodule] Update submodule sonic-swss-common to the latest HEAD aut…
mssonicbld May 30, 2026
fd56f18
[submodule] Update submodule sonic-gnmi to the latest HEAD automatica…
mssonicbld May 30, 2026
04534d7
[Arista] Add 'sai_instru_stat_accum_enable=1' to Arista DNX SKUs (#27…
arista-nwolfe May 30, 2026
df7c9a8
[submodule] Update submodule sonic-redfish to the latest HEAD automat…
mssonicbld May 31, 2026
302cfbc
[submodule] Update submodule sonic-gnmi to the latest HEAD automatica…
mssonicbld May 31, 2026
a35c6ed
[submodule] Update submodule sonic-swss to the latest HEAD automatica…
mssonicbld May 31, 2026
499d4fc
[Mellanox] [SED] Change/Reset SED password CLI (#25260)
benle7 May 31, 2026
24ef6ea
[Marvell-teralynx] Update SAI debian and SDK driver to release 1.18.1…
pavannaregundi Jun 1, 2026
b081bf5
DNS: Fix DNS_OPTIONS schema to allow ConfigDB/Redis serialization + l…
bhouse-nexthop Jun 1, 2026
8d9637d
[build] Remove unneccessary docker run command in Makefile.work (#27574)
liushilongbuaa Jun 1, 2026
b93b9f5
[ci/build]: Upgrade SONiC package versions (#27622)
mssonicbld Jun 1, 2026
98138c8
[submodule] Update submodule sonic-stp to the latest HEAD automatical…
mssonicbld Jun 1, 2026
c3e42ba
[Nexthop] NH-4220 - Log ASIC power good, set DP_PWR_ON (#27102)
antonio-nexthop Jun 1, 2026
80a8935
Ensure ASIC come out of reset before bcm drivers (#27451)
lotus-nexthop Jun 1, 2026
5712530
Add PDDF SPI support for Nexthop platforms (#26927)
domingo-nexthop Jun 1, 2026
c5922cb
[pddf] add support for i2c-xiic with FPGA-version-gated MSI (#27437)
domingo-nexthop Jun 1, 2026
40f1708
Upgrade VS syncd containers to Trixie (#26398)
saiarcot895 Jun 1, 2026
b662f06
[Mellanox] Add support for Mellanox-SN5640-C512X2, Mellanox-SN5640-C5…
sschlafman Jun 1, 2026
d23c035
[interfaces.j2]: Skip syslog policy rule for non-management VRFs (#27…
Bojun-Feng Jun 1, 2026
f165acf
[orchagent] Disable IPinIP decap config only for Mellanox backend non…
thisptr-sh Jun 1, 2026
e908c28
[FC] Move DPU counter defaults to init_cfg.json (#20492) (#27387)
chartsai-nvidia Jun 1, 2026
4383313
ci: enable baseline for vpp (#27427)
auspham Jun 2, 2026
8a5e931
[docker-ptf] Push PR built dock-ptf image to registry (#27463)
opcoder0 Jun 2, 2026
8e11505
Add cpld/fpga device mount for pmon container (#25999)
jackson-micas Jun 2, 2026
eca6da8
[submodule] Update submodule platform/vpp to the latest HEAD automati…
mssonicbld Jun 2, 2026
276b99b
[submodule] Update submodule wpasupplicant/sonic-wpa-supplicant to th…
mssonicbld Jun 2, 2026
a209033
[submodule] Update submodule sonic-platform-common to the latest HEAD…
mssonicbld Jun 2, 2026
016de9f
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld Jun 2, 2026
5379856
Yang model for macmoveguard config (#27530)
sudheer-nexthop Jun 2, 2026
e0c18b1
[ragile] Replace os.popen with subprocess.Popen and add unit tests (#…
mal0b3 Jun 2, 2026
506a5b7
[submodule] Update submodule sonic-sairedis to the latest HEAD automa…
mssonicbld Jun 2, 2026
0f8ad86
[EVPN-MH] Add EVPN-MH FRR patch support (#27544)
tahmed-dev Jun 2, 2026
91e9cdb
[sonic-frr] Enable FRR tcmalloc build by default (#27580)
deepak-singhal0408 Jun 2, 2026
3447ef8
Skip generating L1 config on NH-5010 when it is VS platform (#27591)
BYGX-wcr Jun 2, 2026
c5e1070
[submodule] Update submodule sonic-mgmt-common to the latest HEAD aut…
mssonicbld Jun 3, 2026
7678119
add cpo bailly device (#27517)
KroosMicas Jun 3, 2026
ea4acb6
[Broadcom] Bump XGS SAI to 15.2.0 / SDK 6.5.35 (#27465)
Gfrom2016 Jun 3, 2026
3f9152c
[nvidia-bmc] Implement ast2700 SONiC platform API (#27604)
Yakiv-Huryk Jun 3, 2026
99d604e
[docker] Avoid slow docker restarts from netfilter readiness check
rameshraghupathy Jun 3, 2026
47b60b0
[docker-ptf] re-add gnmic, built from openconfig/gnmic main (#27340)
ronan-nexthop Jun 3, 2026
572ffc1
[sflow]: Added yang model support to set loopback interface as agent …
purush-nexthop Jun 3, 2026
9153511
[marvell-teralynx] Add SDK common config support (#24879)
Naveen-Rampuram Jun 3, 2026
c01ecb6
[restapi-sidecar]: Remove duplicate libswsscommon dependencies (#27705)
qiluo-msft Jun 4, 2026
48df105
[docker-fpm-frr]: Fix tcmalloc package name for Trixie armhf (#27704)
deepak-singhal0408 Jun 4, 2026
b5e09ff
[Arista] Add sai_switch_pcie_hotswap_disable: 1 to TH5 platforms (#27…
byu343 Jun 4, 2026
5785463
Add tuning file to Quicksilver platforms (#22956)
kewei-arista Jun 4, 2026
0554621
Update static_th values for TH5-512 hwskus (#27504)
rgarofano-arista Jun 4, 2026
505b72f
[H6-128]: Remove Ethernet1025 from device files in O256/P128 (#27670)
dgodwin-nokia Jun 4, 2026
ae9055b
H6-128: Add media_settings.json and optics_si_settings.json (#27581)
dgodwin-nokia Jun 4, 2026
32d8a8a
Fix grpc version installed in the pmon container (#27698)
saiarcot895 Jun 5, 2026
e2cff01
[submodule] Update submodule platform/vpp to the latest HEAD automati…
mssonicbld Jun 5, 2026
ccb5689
[submodule] Update submodule sonic-host-services to the latest HEAD a…
mssonicbld Jun 5, 2026
dfd5069
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld Jun 5, 2026
cfb747f
[submodule] Update submodule dhcpmon to the latest HEAD automatically…
mssonicbld Jun 5, 2026
3c57b74
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 5, 2026
0a5f376
[submodule] Update submodule sonic-platform-common to the latest HEAD…
mssonicbld Jun 5, 2026
0f1a716
[submodule] Update submodule sonic-restapi to the latest HEAD automat…
mssonicbld Jun 5, 2026
163b84e
[submodule] Update submodule sonic-linux-kernel to the latest HEAD au…
mssonicbld Jun 5, 2026
7355c30
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld Jun 5, 2026
d7e4984
[Arista] Moby: enable polling of ASIC sensors (#26908)
byu343 Jun 5, 2026
11d6baa
Cleanup PROCESS_HEALTH table in statedb during swss start (#27657)
prabhataravind Jun 5, 2026
a864af7
[yang][orchagent]: Consolidate route performance knobs to SYSTEM_DEFA…
deepak-singhal0408 Jun 5, 2026
ed8767c
[sonic-yang-models]: Enforce PORT leafref only for local VOQ_QUEUE en…
arlakshm Jun 5, 2026
5f7d775
[submodule] Update submodule sonic-swss-common to the latest HEAD aut…
mssonicbld Jun 6, 2026
9113519
[submodule] Update submodule sonic-sairedis to the latest HEAD automa…
mssonicbld Jun 6, 2026
8d1b37c
Fix system manager protocol buffer race under parallel make (#27722)
stephenxs Jun 7, 2026
ca8d702
Update credo version to v1.2.10 (#27381)
arista-hpandya Jun 8, 2026
8183fe3
[Mellanox] Remove force power off during ONIE upgrade (#27411)
gpunathilell Jun 8, 2026
dd62c37
[nvidia-bluefield] Remove legacy console=hvc0 from BF3 DPU kernel com…
chartsai-nvidia Jun 8, 2026
2f1c550
[nvidia-bluefield] Add ability to update aging interval (#25869)
vivekrnv Jun 8, 2026
3afc8bc
[Mellanox] Support Mellanox-SN6600_LD-P128C2 for x86_64-nvidia_sn660…
stephenxs Jun 8, 2026
dd9d1d5
Support Mellanox-SN6600_LD-P64O128C2 (#27275)
stephenxs Jun 8, 2026
61e573d
[submodule] Update submodule sonic-platform-common to the latest HEAD…
mssonicbld Jun 8, 2026
fd8f197
[submodule] Update submodule sonic-sairedis to the latest HEAD automa…
mssonicbld Jun 8, 2026
c7d5fe6
[smartswitch]: Add dpu_auto_recovery flag to SmartSwitch NPU default …
vvolam Jun 8, 2026
6b5e2b7
[mux] write_standby.py: silent no-op on non-dualToR --shutdown bgp (#…
kalash-nexthop Jun 9, 2026
08796db
[Mellanox][Smartswitch] Add blacklist for dpu kernel module to preven…
gpunathilell Jun 9, 2026
37f1afb
[Mellanox] [logging] mellanox-fw-manager: surface and parse mlxfwmana…
yizhenzha Jun 9, 2026
92c9d20
[202605] Update 202605 related templates and documentation (#27699)
mssonicbld Jun 9, 2026
2a6fc3e
[submodule] Update submodule sonic-linux-kernel to the latest HEAD au…
mssonicbld Jun 9, 2026
a235fde
[submodule] Update submodule sonic-mgmt-framework to the latest HEAD …
mssonicbld Jun 9, 2026
be110c9
[submodule] Update submodule sonic-swss-common to the latest HEAD aut…
mssonicbld Jun 9, 2026
d7bb82d
[rules] Remove libyang1, keep only libyang3 (#27629)
bhouse-nexthop Jun 9, 2026
73dc29f
installer: fix NVMe partition umount and partprobe retry in create_de…
DavidZagury Jun 9, 2026
cc080f3
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 9, 2026
a5d37e4
[submodule] Update submodule sonic-sairedis to the latest HEAD automa…
mssonicbld Jun 10, 2026
90f8474
gbsyncd: use RESTORE REPLACE when cloning FEATURE entries (#27317)
anamehra Jun 10, 2026
b287dcb
[initramfs] Add initramfs hook to log more info for blockdev wait iss…
byu343 Jun 10, 2026
2005cfa
[submodule] Update submodule sonic-gnmi to the latest HEAD automatica…
mssonicbld Jun 10, 2026
906ee34
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld Jun 10, 2026
8f5e48e
[submodule] Update submodule sonic-sairedis to the latest HEAD automa…
mssonicbld Jun 10, 2026
2a718e6
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 10, 2026
5c54208
[Nokia][pmon] Update Nokia sonic-platform submodule (#27741)
fzhou-nokia Jun 10, 2026
d74969d
[Mellanox] Update SAI/SDK/FW/MFT/SIMX versions (#27810)
DannyIsa Jun 10, 2026
4e1fffb
[multiasic][rsyslog] Restart the rsyslog.service for multiasic platfo…
mlok-nokia Jun 10, 2026
d0280b8
chore: fix security issue with Go stdlib docker-ptf (#27801)
auspham Jun 11, 2026
6f2bc46
[submodule] Update submodule sonic-linux-kernel to the latest HEAD au…
mssonicbld Jun 11, 2026
0761ba1
[submodule] Update submodule sonic-platform-common to the latest HEAD…
mssonicbld Jun 11, 2026
dc48dfb
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld Jun 11, 2026
ac47de0
Tell p4lang to use protobuf and grpcio installed via pip (#27790)
saiarcot895 Jun 11, 2026
b4b7c88
[submodule] Update submodule sonic-host-services to the latest HEAD a…
mssonicbld Jun 11, 2026
eb4fd89
Add new sku for SmartSwitch Mellanox-SN4280-O4X96 (#27521)
AbdulRouff-Nvidia Jun 11, 2026
855cdbc
[commonlib] Add libnexthopgroup (sonic-fib) to lib-packages target an…
LARLSN Jun 11, 2026
219a392
[Arista] Update sonic-platform-modules-arista submodule (#27687)
arista-hpandya Jun 12, 2026
b94526c
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld Jun 12, 2026
ed3fe79
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 12, 2026
b119a24
[submodule] Update submodule sonic-linux-kernel to the latest HEAD au…
mssonicbld Jun 12, 2026
70b79db
[submodule] Update submodule sonic-sairedis to the latest HEAD automa…
mssonicbld Jun 12, 2026
bf7bc54
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld Jun 12, 2026
c43b278
Fix p4lang file removal path (#27829)
saiarcot895 Jun 12, 2026
9941378
[EVPN-MH] Add FRR bgpd crash fix patch for EVPN MH path handling (#27…
bdfriedman Jun 12, 2026
7640bc1
[Nexthop] add initial NH-4210 platform support (#27154)
yifan-nexthop Jun 12, 2026
6687a0c
Force PFCWD to use software recovery path on NH-5010 SKUs (#27057)
pinky-nexthop Jun 12, 2026
f6aebc2
Override bootconf env variable from installer.conf (#27740)
nats-nokia Jun 12, 2026
e024fc0
Update pddf sfp to follow new convention for sfputil hardware lpmode …
abhi-nexthop Jun 12, 2026
aabe765
[aspeed] Resolve bootconf from device tree for FIT boot (#27814)
william8545 Jun 12, 2026
d5cbd2a
[init-cfg] Default switch-BMC platforms to NetworkBmc device type (#2…
william8545 Jun 12, 2026
2c3baf8
[submodule] Update submodule sonic-platform-common to the latest HEAD…
mssonicbld Jun 13, 2026
43a5b17
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 13, 2026
5eae3f8
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld Jun 13, 2026
bc1c3e2
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld Jun 13, 2026
bf4000d
[ci/build]: Upgrade SONiC package versions (#27876)
mssonicbld Jun 13, 2026
aebfc8b
[build]: Fix incorrect onie loading for 6-asic kvm image (#27866)
oplklum Jun 13, 2026
3e45d28
[Mellanox] Enable amd_iommu for SN6810 platform (#27843)
Junchao-Mellanox Jun 13, 2026
461b267
[nvidia-bluefield] Update MFT version to 4.36.0-147 (#27821)
DannyIsa Jun 13, 2026
766647e
Fix sonic-swss-common builds (#27836)
bgallagher-nexthop Jun 13, 2026
f9c0f12
[submodule] Update submodule sonic-swss-common to the latest HEAD aut…
mssonicbld Jun 14, 2026
6c402ca
[Aspeed BMC] Exclude ztp.service to fix systemd-sonic-generator boot …
william8545 Jun 14, 2026
7e63875
[Mellanox] chassis: fall back to EEPROM part number when VPD data is …
william8545 Jun 14, 2026
f50f78b
[aspeed] TFTP installer: verified success signal and default auto-reb…
william8545 Jun 14, 2026
6341471
add a pipeline to build and publish docker-ptf (#27888)
yijingyan2 Jun 15, 2026
83a34e5
[Mellanox] [SONiC BMC] Support BMC side and align host side for usb0 …
benle7 Jun 15, 2026
0f6cd5e
[Mellanox] Integrate HW-MGMT Version 7.0060.1047 (#27627)
DannyIsa Jun 15, 2026
b070d9f
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 15, 2026
ac10730
Add ENABLE_FRR_SNMP_AGENT build option to disable BGP4-MIB (#27877)
securely1g Jun 15, 2026
3ea58a0
frr: enable LLGR helper-only mode on UpperRegionalHub (#27858)
abdosi Jun 15, 2026
cca9ec0
[minigraph/device_info] Fix is_chassis() and parse device type for Su…
abdosi Jun 15, 2026
31ad094
Enable SYS_PTRACE in frr, orchagent, and teamd (#27842)
croos12 Jun 15, 2026
8a52790
Update Pillow to address CVE-2023-44271 (#27688)
opcoder0 Jun 16, 2026
3ff318a
[broadcom] Bump legacy-th SAI to 13.2.1.120 (OCP1.18.1 compat) (#27875)
lipxu Jun 16, 2026
92d0278
[submodule] Update submodule dhcprelay to the latest HEAD automatical…
mssonicbld Jun 16, 2026
b2c7c18
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld Jun 16, 2026
4eb2f41
[submodule] Update submodule sonic-restapi to the latest HEAD automat…
mssonicbld Jun 16, 2026
5c48377
[submodule] Update submodule sonic-snmpagent to the latest HEAD autom…
mssonicbld Jun 16, 2026
a1b0665
[Mellanox] mlnx-fw-manager.service: escape backslashes in ExecConditi…
yizhenzha Jun 16, 2026
6f16438
[Mellanox][docker-syncd-mlnx-rpc] pin ptf_nn_agent.py to specific ver…
dovsianko-nvda Jun 16, 2026
add05b6
[Mellanox] Add PDB (Power Distribution Board) definition to SN6810_LD…
Junchao-Mellanox Jun 16, 2026
6b03f2c
[Mellanox] Update pcie.yaml for SN6810_LD hardware and SimX platforms…
Junchao-Mellanox Jun 16, 2026
213c24d
[Mellanox] Fix thermalctld ValueError when reading sai.profile during…
ganglyu Jun 16, 2026
9c2ebde
[Mellanox] Fix BMC import issue (#27721)
stephenxs Jun 16, 2026
60d2077
[Mellanox] Fix ThermalUpdater ASIC temp read when STATE_DB has N/A (#…
jianyuewu Jun 16, 2026
740f17f
[submodule] Update submodule sonic-platform-common to the latest HEAD…
mssonicbld Jun 16, 2026
eb891ff
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 16, 2026
dde7a29
[submodule] Update submodule linkmgrd to the latest HEAD automaticall…
mssonicbld Jun 16, 2026
d88fa59
[submodule] Update submodule sonic-bmp to the latest HEAD automatical…
mssonicbld Jun 16, 2026
3300d5b
ci: add all to include_jobs docker-sonic-mgmt PR test (#27795)
auspham Jun 16, 2026
b5e64cb
[submodule] Update submodule sonic-dbsyncd to the latest HEAD automat…
mssonicbld Jun 16, 2026
dd2576f
[submodule] Update submodule sonic-host-services to the latest HEAD a…
mssonicbld Jun 16, 2026
e4f3ac7
[submodule] Update submodule sonic-gnmi to the latest HEAD automatica…
mssonicbld Jun 16, 2026
3c512a4
Add config support to bind gNMI and Telemetry servers to a VRF (#23867)
spandan-nexthop Jun 16, 2026
0f63ae8
[rsyslog] Prevent RELP backpressure from blocking containers (#27408)
rustiqly Jun 16, 2026
cfd6583
[build_debian.sh] remove grpc from host (#27561)
jon-nokia Jun 16, 2026
f7ebc0a
Added bootconf variable to Nexthop installer.conf (#27602)
shreyansh-nexthop Jun 16, 2026
f1d42c1
[submodule] Update submodule platform/vpp to the latest HEAD automati…
mssonicbld Jun 17, 2026
921876f
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld Jun 17, 2026
1b3f437
[submodule] Update submodule sonic-py-swsssdk to the latest HEAD auto…
mssonicbld Jun 17, 2026
97fd360
sysmonitor:wait for dbus and FEATURE subscriptions (#27490)
gpunathilell Jun 17, 2026
9665a5f
[submodule] Update submodule sonic-stp to the latest HEAD automatical…
mssonicbld Jun 17, 2026
c622ac6
[submodule] Update submodule sonic-snmpagent to the latest HEAD autom…
mssonicbld Jun 17, 2026
8f89c0b
[submodule] Update submodule sonic-linux-kernel to the latest HEAD au…
mssonicbld Jun 17, 2026
220b4d8
Add support for Arista-7050SX3 platforms (#26659)
vivekverma-arista Jun 18, 2026
1a90a80
docker-sonic-vs: load config_db.json from /var/sonic at startup
securely1g Mar 7, 2026
ba82b0c
Fix show version: add debian_version at build time, kernel_version at…
securely1g Mar 2, 2026
3328447
Fix build_version: use SONIC_IMAGE_VERSION instead of undefined SONIC…
securely1g Mar 2, 2026
0f59ce1
Add lldpd and _DOCKER += feature composition to docker-sonic-vs
securely1g Mar 6, 2026
fcae7c2
docker-sonic-vs: install sudo package
securely1g Mar 7, 2026
a212c9a
docker-sonic-vs: use _INCLUDE_DOCKER for FRR (docker-fpm-frr)
securely1g Mar 8, 2026
da38c42
docker-sonic-vs: use _INCLUDE_DOCKER for teamd (docker-teamd)
securely1g Mar 8, 2026
53eefdf
docker-sonic-vs: copy constants.yml into image for bgpcfgd
securely1g Mar 9, 2026
e7c6299
docker-sonic-vs: use _INCLUDE_DOCKER for NAT (docker-nat)
securely1g Mar 8, 2026
e8a595e
docker-sonic-vs: use _INCLUDE_DOCKER for sflow (docker-sflow)
securely1g Mar 8, 2026
ebb374b
docker-sonic-vs: use _INCLUDE_DOCKER for swss (docker-orchagent)
securely1g Mar 14, 2026
9056b50
docker-sonic-vs: use _INCLUDE_DOCKER for database (docker-database)
securely1g Mar 14, 2026
6d0ed35
Fix orchagent watchdog: add stdout_capture_maxbytes for heartbeat det…
securely1g Apr 12, 2026
0f268a5
docker-sonic-vs: create /zmq_swss directory for P4Orch ZMQ sockets
securely1g Apr 21, 2026
9f48af9
slave.mk: fix package name detection for pyproject.toml-based packages
securely1g Jun 13, 2026
ef41a30
[bgpcfgd] fix pgrep self-match race causing spurious "bfdd is not run…
croos12 Jun 18, 2026
9d8d24a
[Platform/Micas] add TH6 m2-w6950-128oc and m2-w6951-64hc-cp (#27734)
jackson-micas Jun 18, 2026
e7e2569
rules: update FIPS trixie version to 1.9.4 (#27944)
xq9mend Jun 18, 2026
22d6f74
[BMC] bind redis database in BMC on bmc0 internal link (#27907)
judyjoseph Jun 19, 2026
0790915
[build] upgrade p4lang-pi package version (#27945)
yijingyan2 Jun 19, 2026
be9722a
[submodule] Update submodule sonic-redfish to the latest HEAD automat…
mssonicbld Jun 19, 2026
7ea4cfc
[Nokia][pmon]Update Nokia sonic-platform submodule (#27896)
Pavan-Nokia Jun 19, 2026
00f246c
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 20, 2026
61abbfb
[submodule] Update submodule platform/vpp to the latest HEAD automati…
mssonicbld Jun 20, 2026
33c6847
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld Jun 20, 2026
15ea36a
[submodule] Update submodule sonic-host-services to the latest HEAD a…
mssonicbld Jun 20, 2026
1f9c84e
[submodule] Update submodule sonic-platform-daemons to the latest HEA…
mssonicbld Jun 20, 2026
e5844fb
[submodule] Update submodule sonic-redfish to the latest HEAD automat…
mssonicbld Jun 20, 2026
3e6fb3b
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 20, 2026
a7b31ca
[submodule] Update submodule sonic-swss to the latest HEAD automatica…
mssonicbld Jun 20, 2026
71d0d05
build: remove libgrpc and libprotobuf runtime packages from base imag…
xq9mend Jun 20, 2026
fb4079f
[yang] Restrict ssh_string username to POSIX-compliant format (#26663)
KeshavSM10 Jun 20, 2026
6bbc46e
supervisor-proc-exit-listener: handle PROCESS_STATE_FATAL to restart …
xq9mend Jun 20, 2026
0cd3623
[submodule] Update submodule sonic-linux-kernel to the latest HEAD au…
mssonicbld Jun 20, 2026
e92b1b5
[ci/build]: Upgrade SONiC package versions (#28003)
mssonicbld Jun 20, 2026
28778aa
[build] Support building from a git worktree (#28007)
securely1g Jun 21, 2026
855435b
[submodule] Update submodule sonic-gnmi to the latest HEAD automatica…
mssonicbld Jun 21, 2026
931dbfb
[broadcom] Enable build cache for legacy-TH packages (#27972)
lipxu Jun 22, 2026
7e3ed9e
[EVPN-MH] Add EVPN-MH YANG model support (#27543)
tahmed-dev Jun 22, 2026
97de158
[Broadcom] Upgrade Broadcom xgs SAI version to 15.2.0.0.0.0.3.1 (#28021)
aaronber0614 Jun 22, 2026
ac08dec
[system-health] Add periodic full-scan backstop so transient service …
BYGX-wcr Jun 22, 2026
54bee1d
[sflow] Fix hsflowd db_addWriteCB recursion / stack overflow on high-…
yxieca Jun 22, 2026
14dceec
[ci] supporting pull image from registry for test instead of loading …
yijingyan2 Jun 23, 2026
df3742d
[dhcp_server] make dhcpservd readiness check idempotent (#27684)
chartsai-nvidia Jun 23, 2026
bcaf9b9
[nvidia-bluefield] Ignore pdb in arm64-nvda_bf-bf3comdpu Health Check…
croos12 Jun 23, 2026
bab2d5f
[Mellanox] Increase /var/log partition size for SN6810_LD (#27849)
Junchao-Mellanox Jun 23, 2026
ec9a23d
Fix service_checker ignoring group: entries in critical_processes (#2…
frank-nexthop Jun 23, 2026
d642260
update OT thresholds for NH-5010 (#27727)
roy-nexthop Jun 23, 2026
dbc5786
[Mellanox] Mellanox-SN5640-C508O1X2: switch to FW-control (#27824)
ShauliTaragin Jun 23, 2026
c44ed7b
[Mellanox] Enable warm-reboot on SN5640 SKUs (#27860)
nazariig Jun 23, 2026
532e982
[submodule] Update submodule sonic-dash-ha to the latest HEAD automat…
mssonicbld Jun 23, 2026
4d5902e
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 23, 2026
4a8591c
[build] Rebuild cached targets when only build flags change (#27941)
croos12 Jun 23, 2026
cb47b47
add FT2 support for O128 (#27588)
dakotac-arista Jun 23, 2026
f0dd523
[docker-ptf]: Upgrade gnmic golang.org/x/* deps to fix security vulne…
auspham Jun 23, 2026
8314b90
Fix the name of the switchhost module. Remove the module index (#28016)
chander-nexthop Jun 23, 2026
18c3365
Fix cyclic dependancy in systemd service (#28017)
chander-nexthop Jun 23, 2026
2b10952
Fix the console speed for the Nexthop's BMC card (#28019)
chander-nexthop Jun 23, 2026
e3df823
[BMC] Create /host/bmc dir before pmon docker create (#27820)
judyjoseph Jun 23, 2026
c9c9f77
[docker-ptf] Resolve python-saithrift egg path dynamically (fix switc…
lipxu Jun 23, 2026
5ea53e5
[memory_checker] Skip containers removed during listing to avoid spur…
antonio-nexthop Jun 24, 2026
aa7db8c
[submodule] Update submodule sonic-gnmi to the latest HEAD automatica…
mssonicbld Jun 24, 2026
1415068
[submodule] Update submodule sonic-platform-common to the latest HEAD…
mssonicbld Jun 24, 2026
67541ed
[submodule] Update submodule sonic-utilities to the latest HEAD autom…
mssonicbld Jun 24, 2026
196ff17
[pddf] cpldmux: Suppress routine channel switching logs by default (#…
nonodark Jun 24, 2026
d85fc71
[nvidia-bluefield] Add syncd to critical process list (#28053)
vivekrnv Jun 24, 2026
9f2ad29
sysctl: enable ignore_routes_with_linkdown for IPv4 and IPv6 (#27420)
rminnikanti Jun 24, 2026
4abb4d7
Docker: Prevent first-boot platform startup failures by disabling IPv…
rameshraghupathy Jun 24, 2026
41622c3
[Micas] add TH5 buffer template (#28069)
yifei-micas Jun 25, 2026
bb0715a
modify cpo bailly device (#27808)
KroosMicas Jun 25, 2026
7ba36bd
[Nokia-vs] Enhancements on fpga, platform temp alg and error fixes (#…
hehuang-nokia Jun 25, 2026
316ed5a
Local ARS (Adaptive Routing and Switching)
VladimirKuk May 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
50 changes: 50 additions & 0 deletions .azure-pipelines/azure-pipelines-build-alpinevs.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
pr: none
trigger: none


name: $(TeamProject)_$(Build.DefinitionName)_$(SourceBranchName)_$(Date:yyyyMMdd)$(Rev:.r)

resources:
repositories:
- repository: buildimage
type: github
name: sonic-net/sonic-buildimage
endpoint: sonic-net
ref: master


variables:
- template: .azure-pipelines/azure-pipelines-repd-build-variables.yml@buildimage
- template: .azure-pipelines/template-variables.yml@buildimage
- name: CACHE_MODE
value: rcache
- name: ENABLE_FIPS
value: y
- name: BUILD_BRANCH
${{ if eq(variables['Build.Reason'], 'PullRequest') }}:
value: $(System.PullRequest.TargetBranch)
${{ else }}:
value: $(Build.SourceBranchName)


parameters:
- name: SUBMODULE
type: string
default: ' '

- name: COMMIT_ID
type: string
default: ' '


stages:
- stage: BuildAlpineVS
pool: sonicso1ES-amd64
jobs:
- template: azure-pipelines-build.yml
parameters:
buildOptions: 'USERNAME=admin SONIC_BUILD_JOBS=$(nproc) ${{ variables.VERSION_CONTROL_OPTIONS }}'
jobGroups:
- name: alpinevs
SUBMODULE: ${{ parameters.SUBMODULE }}
COMMIT_ID: ${{ parameters.COMMIT_ID }}
16 changes: 16 additions & 0 deletions .azure-pipelines/azure-pipelines-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,10 @@ jobs:
dbg_image: yes
asan_image: yes

- name: alpinevs
variables:
dbg_image: yes

- name: barefoot
variables:
docker_syncd_rpc_image: yes
Expand Down Expand Up @@ -115,6 +119,12 @@ jobs:
variables:
PLATFORM_ARCH: arm64

- name: aspeed-arm64
pool: sonicso1ES-arm64
variables:
PLATFORM_NAME: aspeed
PLATFORM_ARCH: arm64

- name: vpp
variables:
dbg_image: yes
Expand All @@ -127,6 +137,10 @@ jobs:
if echo $(GROUP_NAME) | grep mellanox; then
BUILD_OPTIONS="$BUILD_OPTIONS INCLUDE_DHCP_SERVER=y"
fi
# ENABLE_SBOM=y emits CycloneDX SBOMs alongside each .bin /
# .img / .swi / .tar and standalone SBOMs for docker-ptf /
# docker-ptf-sai / docker-sonic-mgmt when those are built.
BUILD_OPTIONS="$BUILD_OPTIONS ENABLE_SBOM=y"
if [ $(GROUP_NAME) == pensando ]; then
make $BUILD_OPTIONS target/sonic-pensando.tar
elif [ $(GROUP_NAME) == vs ]; then
Expand Down Expand Up @@ -159,6 +173,8 @@ jobs:
mv target/sonic-vpp.img.gz target/sonic-vpp-dbg.img.gz
fi
make $BUILD_OPTIONS target/sonic-vpp.img.gz
elif [ $(GROUP_NAME) == alpinevs ]; then
make $BUILD_OPTIONS target/sonic-alpinevs.img.gz
else
if [ $(dbg_image) == yes ]; then
make $BUILD_OPTIONS INSTALL_DEBUG_TOOLS=y target/sonic-$(GROUP_NAME).bin
Expand Down
52 changes: 35 additions & 17 deletions .azure-pipelines/azure-pipelines-image-template.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ jobs:
- script: |
[ -n "$OVERRIDE_BUILD_OPTIONS" ] && OVERRIDE_BUILD_OPTIONS=$(OVERRIDE_BUILD_OPTIONS)
BUILD_OPTIONS="$(BUILD_OPTIONS) $OVERRIDE_BUILD_OPTIONS"
if [ -n "$(CACHE_MODE)" ] && echo $(PLATFORM_AZP) | grep -E -q "^(vs|broadcom|mellanox|marvell-prestera-armhf|marvell-prestera-arm64|vpp|nvidia-bluefield)$"; then
if [ -n "$(CACHE_MODE)" ] && echo $(PLATFORM_AZP) | grep -E -q "^(vs|broadcom|mellanox|marvell-prestera-armhf|marvell-prestera-arm64|vpp|nvidia-bluefield|alpinevs)$"; then
CACHE_OPTIONS="SONIC_DPKG_CACHE_METHOD=$(CACHE_MODE) SONIC_DPKG_CACHE_SOURCE=/nfs/dpkg_cache/$(PLATFORM_AZP)"
BUILD_OPTIONS="$BUILD_OPTIONS $CACHE_OPTIONS"
fi
Expand Down Expand Up @@ -78,38 +78,56 @@ jobs:
postSteps:
- script: |
BUILD_REASON=$(Build.Reason)
PTF_MODIFIED_IN_PR="False"
echo "Build.Reason = $BUILD_REASON"
echo "Build.DefinitionName = $BUILD_DEFINITIONNAME"
if [[ "$BUILD_REASON" == "PullRequest" ]]; then
echo "Checking for changes to dockers/docker-ptf/Dockerfile.j2 in PR..."
# Get the target branch and check for changes
TARGET_BRANCH="origin/$(System.PullRequest.TargetBranch)"
echo "Comparing against target branch: $TARGET_BRANCH"
# Fetch target branch to ensure we have the latest
git fetch origin $(System.PullRequest.TargetBranch)
# Check if docker-ptf Dockerfile.j2 has changes
echo "Checking for changes to docker-ptf in PR..."
# Set PTF_MODIFIED to True if docker-ptf was not built from cache, otherwise set it to False
# NOTE: The PTF_MODIFIED template parameter is of type string
# Ensure to set it to "True" or "False" (not boolean true/false)
if git diff --name-only $TARGET_BRANCH...HEAD | grep -q "dockers/docker-ptf/Dockerfile.j2"; then
echo "docker-ptf/Dockerfile.j2 has been modified in this PR"
echo "##vso[task.setvariable variable=PTF_MODIFIED;isOutput=true]True"
else
echo "docker-ptf/Dockerfile.j2 has not been modified in this PR"
if [ ! -f "target/docker-ptf.gz.log" ]; then
echo "docker-ptf was not built in this PR, setting PTF_MODIFIED to False"
echo "##vso[task.setvariable variable=PTF_MODIFIED;isOutput=true]False"
PTF_MODIFIED_IN_PR="False"
else
if grep -q "CACHE::LOADED" target/docker-ptf.gz.log; then
echo "docker-ptf was built from cache in this PR, setting PTF_MODIFIED to False"
echo "##vso[task.setvariable variable=PTF_MODIFIED;isOutput=true]False"
PTF_MODIFIED_IN_PR="False"
else
echo "docker-ptf was not built from cache in this PR, setting PTF_MODIFIED to True"
echo "##vso[task.setvariable variable=PTF_MODIFIED;isOutput=true]True"
PTF_MODIFIED_IN_PR="True"
fi
fi
else
echo "Not a PR build, setting PTF_MODIFIED to false"
echo "##vso[task.setvariable variable=PTF_MODIFIED;isOutput=true]False"
PTF_MODIFIED_IN_PR="False"
fi

echo "PTF_MODIFIED_IN_PR = $PTF_MODIFIED_IN_PR"
# Prepare publish settings
PORT=443
BRANCH=$(Build.SourceBranchName)
echo "Branch = $BRANCH"
PUSH_DOCKER="False"
if [[ "$BUILD_REASON" != "PullRequest" && "$BUILD_DEFINITIONNAME" == "Azure.sonic-buildimage.official.vs" ]]
then
PORT=443
DOCKERS=$(ls target/docker-ptf.gz)
BRANCH=$(Build.SourceBranchName)
echo "Branch = $BRANCH"
LABELS="$BRANCH"
[[ "$BRANCH" == "master" ]] && LABELS="$LABELS latest"
DOCKERS=$(ls target/docker-ptf.gz)
PUSH_DOCKER="True"
elif [[ "$PTF_MODIFIED_IN_PR" == "True" ]]
then
LABELS="ptf-$SYSTEM_PULLREQUEST_PULLREQUESTNUMBER"
DOCKERS=$(ls target/docker-ptf.gz)
PUSH_DOCKER="True"
else
echo "Not publishing docker images since docker-ptf was not modified in this PR or build definition name is not Azure.sonic-buildimage.official.vs"
fi
if [[ "$PUSH_DOCKER" == "True" ]]; then
for f in $DOCKERS; do
echo $f
echo "Labels = $LABELS"
Expand Down
49 changes: 29 additions & 20 deletions .azure-pipelines/baseline_test/baseline.test.buildimage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,6 +45,10 @@ parameters:
type: boolean
default: true

- name: INCLUDE_JOBS
type: string
default: "all"

variables:
- template: ../azure-pipelines-repd-build-variables.yml
- template: ../template-variables.yml
Expand All @@ -69,19 +73,24 @@ stages:
buildOptions: 'USERNAME=admin SONIC_BUILD_JOBS=$(nproc) BUILD_MULTIASIC_KVM=y INCLUDE_DHCP_SERVER=y ${{ variables.VERSION_CONTROL_OPTIONS }}'
jobGroups:
- name: vs
- template: ../azure-pipelines-build.yml
parameters:
buildOptions: 'USERNAME=admin SONIC_BUILD_JOBS=$(nproc) ${{ variables.VERSION_CONTROL_OPTIONS }}'
jobGroups:
- name: vpp

- stage: Test_round_1
dependsOn: BuildVS
condition: and(succeeded(), and(ne(stageDependencies.BuildVS.outputs['vs.SetVar.SKIP_VSTEST'], 'YES'), in(dependencies.BuildVS.result, 'Succeeded', 'SucceededWithIssues')))
jobs:
- template: .azure-pipelines/pr_test_template.yml@sonic-mgmt
parameters:
GLOBAL_PARAMS:
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
CHECKOUT_SONIC_MGMT: ${{ parameters.CHECKOUT_SONIC_MGMT }}
INCLUDE_JOBS: ${{ parameters.INCLUDE_JOBS }}

- stage: Test_round_2
dependsOn:
Expand All @@ -90,12 +99,12 @@ stages:
jobs:
- template: .azure-pipelines/pr_test_template.yml@sonic-mgmt
parameters:
GLOBAL_PARAMS:
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
CHECKOUT_SONIC_MGMT: ${{ parameters.CHECKOUT_SONIC_MGMT }}
INCLUDE_JOBS: ${{ parameters.INCLUDE_JOBS }}

- stage: Test_round_3
dependsOn:
Expand All @@ -104,12 +113,12 @@ stages:
jobs:
- template: .azure-pipelines/pr_test_template.yml@sonic-mgmt
parameters:
GLOBAL_PARAMS:
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
CHECKOUT_SONIC_MGMT: ${{ parameters.CHECKOUT_SONIC_MGMT }}
INCLUDE_JOBS: ${{ parameters.INCLUDE_JOBS }}

- stage: Test_round_4
dependsOn:
Expand All @@ -118,9 +127,9 @@ stages:
jobs:
- template: .azure-pipelines/pr_test_template.yml@sonic-mgmt
parameters:
GLOBAL_PARAMS:
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
BUILD_REASON: ${{ parameters.BUILD_REASON }}
RETRY_TIMES: ${{ parameters.RETRY_TIMES }}
STOP_ON_FAILURE: ${{ parameters.TEST_PLAN_STOP_ON_FAILURE }}
TEST_PLAN_NUM: ${{ parameters.TEST_PLAN_NUM }}
CHECKOUT_SONIC_MGMT: ${{ parameters.CHECKOUT_SONIC_MGMT }}
INCLUDE_JOBS: ${{ parameters.INCLUDE_JOBS }}
88 changes: 78 additions & 10 deletions .azure-pipelines/build-template.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,52 +83,120 @@ jobs:
sudo apt-get install -y acl
export DOCKER_DATA_ROOT_FOR_MULTIARCH=/data/march/docker
CACHE_OPTIONS="SONIC_DPKG_CACHE_METHOD=${{ parameters.cache_mode }} SONIC_DPKG_CACHE_SOURCE=/nfs/dpkg_cache/${{ parameters.platform }}"
ENABLE_DOCKER_BASE_PULL=y make configure PLATFORM=${{ parameters.platform }} PLATFORM_ARCH=${{ parameters.platform_arch }}
# ENABLE_SBOM=y emits CycloneDX SBOMs alongside every .bin and
# standalone SBOMs for docker-ptf / docker-ptf-sai.
ENABLE_DOCKER_BASE_PULL=y ENABLE_SBOM=y make configure PLATFORM=${{ parameters.platform }} PLATFORM_ARCH=${{ parameters.platform_arch }}
trap "sudo rm -rf fsroot" EXIT

if [ ${{ parameters.platform }} == vs ]; then
if [ ${{ parameters.dbg_image }} == true ]; then
make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) INSTALL_DEBUG_TOOLS=y target/sonic-vs.img.gz && \
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) INSTALL_DEBUG_TOOLS=y target/sonic-vs.img.gz && \
mv target/sonic-vs.img.gz target/sonic-vs-dbg.img.gz
fi

make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) target/docker-sonic-vs.gz target/sonic-vs.img.gz target/docker-ptf.gz
make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) target/docker-ptf-sai.gz
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) target/docker-sonic-vs.gz target/sonic-vs.img.gz target/docker-ptf.gz
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) target/docker-ptf-sai.gz
elif [ ${{ parameters.platform }} == alpinevs ]; then
make USERNAME=admin SONIC_BUILD_JOB=2 $CACHE_OPTIONS ENABLE_SBOM=y target/sonic-alpinevs.img.gz
else
if [ ${{ parameters.dbg_image }} == true ]; then
make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) INSTALL_DEBUG_TOOLS=y target/sonic-${{ parameters.platform }}.bin && \
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) INSTALL_DEBUG_TOOLS=y target/sonic-${{ parameters.platform }}.bin && \
mv target/sonic-${{ parameters.platform }}.bin target/sonic-${{ parameters.platform }}-dbg.bin
fi
if [ ${{ parameters.swi_image }} == true ]; then
make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) ENABLE_IMAGE_SIGNATURE=y target/sonic-aboot-${{ parameters.platform }}.swi
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) ENABLE_IMAGE_SIGNATURE=y target/sonic-aboot-${{ parameters.platform }}.swi
fi
if [ ${{ parameters.sync_rpc_image }} == true ]; then
make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) ENABLE_SYNCD_RPC=y target/docker-syncd-${{ parameters.platform_short }}-rpc.gz
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) ENABLE_SYNCD_RPC=y target/docker-syncd-${{ parameters.platform_short }}-rpc.gz
# workaround for issue in rules/sairedis.dep, git ls-files will list un-exist files for cache
pushd ./src/sonic-sairedis/SAI
git stash
popd
if [ ${{ parameters.platform }} == broadcom ]; then
make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) ENABLE_SYNCD_RPC=y SAITHRIFT_V2=y target/docker-saiserverv2-brcm.gz
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) ENABLE_SYNCD_RPC=y SAITHRIFT_V2=y target/docker-saiserverv2-brcm.gz
pushd ./src/sonic-sairedis/SAI
git stash
popd
fi
if [ ${{ parameters.platform }} == barefoot ]; then
make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) SAITHRIFT_V2=y ENABLE_SYNCD_RPC=y target/docker-saiserverv2-bfn.gz
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) SAITHRIFT_V2=y ENABLE_SYNCD_RPC=y target/docker-saiserverv2-bfn.gz
pushd ./src/sonic-sairedis/SAI
git stash
popd
fi
fi

make USERNAME=admin $CACHE_OPTIONS SONIC_BUILD_JOBS=$(nproc) target/sonic-${{ parameters.platform }}.bin
make USERNAME=admin $CACHE_OPTIONS ENABLE_SBOM=y SONIC_BUILD_JOBS=$(nproc) target/sonic-${{ parameters.platform }}.bin
fi
displayName: 'Build sonic image'
- script: |
set +e
# Run an SBOM-based vulnerability scan against each SBOM the
# build produced in this pipeline: the platform .bin/.img/.swi
# plus the docker-ptf / docker-ptf-sai test containers when
# the VS group built them. docker-sonic-mgmt is scanned in
# its own pipeline (docker-sonic-mgmt.yml) and is not built
# here. VEX statements under vex/ suppress CVEs that SONiC
# patches fix. Mirrors the legacy trivy policy: MEDIUM+
# severity, fixed-only, fail on remaining unsuppressed
# findings.
OVERALL_RC=0
mkdir -p $(Build.ArtifactStagingDirectory)/sbom-vuln
shopt -s nullglob
# Aggregate SBOMs the build emitted. SONiC produces several
# installer formats — .bin (ONIE), .swi (Arista aboot),
# .img.gz (VS/VPP) — plus standalone test-container SBOMs
# (note the .sbom. infix on the latter, which distinguishes
# them from per-container recipe fragments at
# target/docker-*.gz.cdx.json).
for sbom in \
target/sonic-*.bin.cdx.json \
target/sonic-*.swi.cdx.json \
target/sonic-*.img.gz.cdx.json \
target/docker-*.gz.sbom.cdx.json
do
# Derive a short name for this scan's outputs. Test-container
# SBOMs include a `.sbom` infix on disk (e.g. docker-ptf.gz.sbom.cdx.json)
# to distinguish them from per-container recipe fragments
# (docker-ptf.gz.cdx.json); strip it so the per-artifact
# output names match the underlying artifact extension:
# sonic-broadcom.bin.cdx.json -> sonic-broadcom.bin{.txt,.cdx.json}
# docker-ptf.gz.sbom.cdx.json -> docker-ptf.gz{.txt,.cdx.json}
name=$(basename "$sbom" .cdx.json)
name="${name%.sbom}"
# Azure Pipelines log-folding directive — wrap each SBOM's
# output so the log view shows a collapsible section per
# scan rather than one giant concatenated stream.
echo "##[group]SBOM vuln scan: $name"
python3 scripts/sbom_vuln_scan.py \
--vex vex \
--min-severity medium \
--fail-on medium \
--format both \
--output "$(Build.ArtifactStagingDirectory)/sbom-vuln/${name}.cdx.json" \
"$sbom" | tee "$(Build.ArtifactStagingDirectory)/sbom-vuln/${name}.txt"
RC=${PIPESTATUS[0]}
if [ "$RC" != "0" ]; then OVERALL_RC=$RC; fi
echo "##[endgroup]"
done
exit $OVERALL_RC
# Disabled for now; change to `succeededOrFailed()` to re-enable
# the SBOM-based vulnerability scan step. SBOM emission itself is
# unaffected — the .cdx.json sidecars are still produced by the
# `Build sonic image` step above. Only the post-build scan is
# gated.
condition: false
continueOnError: true
displayName: 'SBOM vulnerability scan'
- template: cleanup.yml
- publish: $(System.DefaultWorkingDirectory)/
artifact: sonic-buildimage.${{ parameters.platform }}
displayName: "Archive sonic image"
- publish: $(Build.ArtifactStagingDirectory)/sbom-vuln
artifact: sbom-vuln-scan-results.${{ parameters.platform }}
displayName: "Archive SBOM vuln-scan results"
condition: always()
continueOnError: true
- script: |
set -x
find target -name "*.log" | xargs -I{} cp {} $(Build.ArtifactStagingDirectory)/
Expand Down
Loading
Loading