Skip to content

Releases: archledger/intel-npu-stack

Intel NPU Stack 0.1.1

Choose a tag to compare

@github-actions github-actions released this 26 Sep 15:53
Immutable release. Only release title and notes can be modified.
b817fe7

Intel NPU Stack 0.1.1

Signed Fedora 44 x86_64 packages for the Intel NPU on PCI 8086:643e, served from https://archledger.github.io/intel-npu-stack/0.1.1/. That directory has no index page; SHA256SUMS lists every other file in it, and SHA256SUMS.asc is its signature.

Install

Run as a normal user; the installer asks for privileges only when it applies the plan:

(
    set -eu
    umask 077
    bootstrap_directory=$(mktemp -d) || exit 20
    trap 'rm -rf -- "$bootstrap_directory"' EXIT
    trap 'exit 129' HUP
    trap 'exit 130' INT
    trap 'exit 143' TERM
    bootstrap_file=$bootstrap_directory/install.sh
    if ! curl --disable --fail --location --proto '=https' --proto-redir '=https' \
        --connect-timeout 15 --max-time 180 --max-filesize 1048576 \
        --output "$bootstrap_file" -- https://archledger.github.io/intel-npu-stack/0.1.1/install.sh; then exit 20; fi
    [ -f "$bootstrap_file" ] && [ ! -L "$bootstrap_file" ] || exit 20
    if ! printf '%s  %s\n' '8b941589c92420f7719f0be2be9cb870ba6e7234a07f15949c57010e6b22f0fa' "$bootstrap_file" | sha256sum --check --status; then exit 20; fi
    /bin/sh "$bootstrap_file" "$@"
)

The command downloads install.sh, checks its SHA-256 and runs it. install.sh checks the installer binary the same way, and the installer verifies release.json against the release key it carries.

The short form trusts the HTTPS download of install.sh instead of checking its SHA-256; everything after it is checked the same way. curl reports a failed download, but the pipeline exits with the status of sh, so scripts should use the command above:

curl --disable --proto '=https' --proto-redir '=https' -fsSL https://archledger.github.io/intel-npu-stack/0.1.1/install.sh | sh

Verify before running

  1. Download install.sh and install.sh.asc.
  2. Run gpg --status-fd 1 --verify install.sh.asc install.sh with the release public key and check that VALIDSIG names the primary key 1085FBE578732D1CF0C50417A8FE2F718B8763D8.
  3. Read install.sh.
  4. Run sh install.sh --dry-run, then sh install.sh.

Support

  • Platform: Fedora 44 x86_64 (fedora), profile fedora-44-lunar-lake-x86_64 (qualified).
  • Hardware: PCI 8086:643e.
  • Kernel: 7.2.5 up to, not including, 7.3.0 (intel_vpu). Tested: 7.2.5-200.fc44 (upgrade, firmware activation and warm reboot, doctor, removal, rollback, restoration, repeat installation); 7.2.7-200.fc44 (doctor, suspend/resume, cold boot). Other kernels inside the window are admitted by policy, observed by the kernel watcher and need a recorded per-kernel probe.
  • Not supported: kernel 7.3 series and later: requires requalification; unbounded dynamic-batch models compiled without a batch layout on the NPU (issue #20).
  • The full matrix is support-matrix.json.

Digests

File SHA-256
release.json 9aa889d617acd30aaf9cd8848f0cffc5f39b55b966cd89deded3e5862ee12e4a
intel-npu-stack-0.1.1.tar 4505e8046bfb5cac69cba3a41527d2d351af955d9df4505312a052502cb85057
SHA256SUMS 0e1f9479fed5c7636e8e4642d58971f7872539d159112e4155bfc18e75732291
Qualification evidence dcf68c330d2d52aa270cc4f84df671c916d0a4d7c4beba076eb84cf7d52a3afa

Rollback

The Fedora packages this release replaces are kept in evidence/rollback (index evidence/rollback/rollback-index.json). See docs/install-fedora.md, section "Removal and rollback" for removal and rollback.

Verify the release

gh release verify v0.1.1 -R archledger/intel-npu-stack
gh release verify-asset v0.1.1 intel-npu-stack-0.1.1.tar -R archledger/intel-npu-stack
gh attestation verify intel-npu-stack-0.1.1.tar -R archledger/intel-npu-stack
gpg --status-fd 1 --verify SHA256SUMS.asc SHA256SUMS
sha256sum --check --strict SHA256SUMS

Intel NPU Stack 0.1.0

Choose a tag to compare

@github-actions github-actions released this 26 Sep 12:29
Immutable release. Only release title and notes can be modified.
47d72f4

Intel NPU Stack 0.1.0

Signed Fedora 44 x86_64 packages for the Intel NPU on PCI 8086:643e, served from https://archledger.github.io/intel-npu-stack/0.1.0/. That directory has no index page; SHA256SUMS lists every other file in it, and SHA256SUMS.asc is its signature.

Install

Run as a normal user; the installer asks for privileges only when it applies the plan:

(
    set -eu
    umask 077
    bootstrap_directory=$(mktemp -d) || exit 20
    trap 'rm -rf -- "$bootstrap_directory"' EXIT
    trap 'exit 129' HUP
    trap 'exit 130' INT
    trap 'exit 143' TERM
    bootstrap_file=$bootstrap_directory/install.sh
    if ! curl --disable --fail --location --proto '=https' --proto-redir '=https' \
        --connect-timeout 15 --max-time 180 --max-filesize 1048576 \
        --output "$bootstrap_file" -- https://archledger.github.io/intel-npu-stack/0.1.0/install.sh; then exit 20; fi
    [ -f "$bootstrap_file" ] && [ ! -L "$bootstrap_file" ] || exit 20
    if ! printf '%s  %s\n' '05c0f5ffeee515be12eba385fa000795c65e6dd70ccc6d84b4e0ba67d36e7d8e' "$bootstrap_file" | sha256sum --check --status; then exit 20; fi
    /bin/sh "$bootstrap_file" "$@"
)

The command downloads install.sh, checks its SHA-256 and runs it. install.sh checks the installer binary the same way, and the installer verifies release.json against the release key it carries.

Verify before running

  1. Download install.sh and install.sh.asc.
  2. Run gpg --status-fd 1 --verify install.sh.asc install.sh with the release public key and check that VALIDSIG names the primary key 1085FBE578732D1CF0C50417A8FE2F718B8763D8.
  3. Read install.sh.
  4. Run sh install.sh --dry-run, then sh install.sh.

Support

  • Platform: Fedora 44 x86_64 (fedora), profile fedora-44-lunar-lake-x86_64 (qualified).
  • Hardware: PCI 8086:643e.
  • Kernel: 7.2.5 up to, not including, 7.3.0 (intel_vpu). Tested: 7.2.5-200.fc44 (upgrade, firmware activation and warm reboot, doctor, removal, rollback, restoration, repeat installation); 7.2.7-200.fc44 (doctor, suspend/resume, cold boot). Other kernels inside the window are admitted by policy, observed by the kernel watcher and need a recorded per-kernel probe.
  • Not supported: kernel 7.3 series and later: requires requalification; unbounded dynamic-batch models compiled without a batch layout on the NPU (issue #20).
  • The full matrix is support-matrix.json.

Digests

File SHA-256
release.json e55863c559edf6bd192dc4c44986ff899c1eb1ff4e5783ee8e0bdced39b5c15a
intel-npu-stack-0.1.0.tar f5ff1902130b0379198d715622d8c588f98a8ec0d3ff80ebe92905a3073d8de9
SHA256SUMS c0d4192964a6020627006fc95a517800bbca96fb80292f06b320c03d4f929417
Qualification evidence 895c57f403c03c2e71d813d8448e5a68473722d205d58d35f06c417d194c5c50

Rollback

The Fedora packages this release replaces are kept in evidence/rollback (index evidence/rollback/rollback-index.json). See docs/install-fedora.md, section "Removal and rollback" for removal and rollback.

Verify the release

gh release verify v0.1.0 -R archledger/intel-npu-stack
gh release verify-asset v0.1.0 intel-npu-stack-0.1.0.tar -R archledger/intel-npu-stack
gh attestation verify intel-npu-stack-0.1.0.tar -R archledger/intel-npu-stack
gpg --status-fd 1 --verify SHA256SUMS.asc SHA256SUMS
sha256sum --check --strict SHA256SUMS

Release inputs for 0.1.1

Pre-release

Choose a tag to compare

@archledger archledger released this 26 Sep 15:38
Immutable release. Only release title and notes can be modified.
b817fe7

Unsigned inputs for the protected release workflow, which signs and assembles release 0.1.1 from them: the same 15 unsigned RPMs as release 0.1.0 (the matched 1.38.0 stack, 14 runtime and 1 devel), the 12 rollback RPMs, the package, SPDX and source-policy indexes, the notices, and the qualified 0.1.1 profile as candidate.toml. Only candidate.toml differs from the 0.1.0 inputs.

This is not an installable release.

SHA-256 of release-inputs-0.1.1.tar.gz: cb55de81d396615e83932f62186e7e52cba4db7fc0b1849e01c43c8bc9c4122c

Release inputs for 0.1.0

Pre-release

Choose a tag to compare

@archledger archledger released this 26 Sep 04:44
Immutable release. Only release title and notes can be modified.
193ef4f

Unsigned inputs for the protected release workflow, which signs and assembles release 0.1.0 from them: the 15 unsigned RPMs of the matched 1.38.0 stack (14 runtime, 1 devel), the 12 rollback RPMs, the package, SPDX and source-policy indexes, the notices, and the qualified profile as candidate.toml.

This is not an installable release.

SHA-256 of release-inputs-0.1.0.tar.gz: 005a2434f202617ca92320ee5f6e9f53ba54877b6e4cb73859de7db712a76564