meta-forgefirm: the image manifest (/etc/forgefirm-manifest.json)

Every image records the identity of its build inputs. forgefirm-manifest.bbclass
gives a component recipe a per-file source fingerprint (git ls-tree blob ids,
submodules recursed; file:// sources hashed with git hash-object); the kernel
and glowforge.ko publish theirs through do_deploy because kernel-module-split
leaves the module recipe's main package empty. forgefirm-image-manifest.bbclass
assembles the entries with the platform identity - machine, modules directory,
device tree hashes, layer content hashes (meta-forgefirm and the meta-openglow
layers by content, the kas-managed layers by revision) - into
/etc/forgefirm-manifest.json and deploys a copy next to the image. Layer
revisions and dirty flags stay outside the identity, so a rebuild from an
unchanged tree keeps its content hash and the release and dev images of one
build share it. The acceptance tool and the release gate read this file.
This commit is contained in:
ScottW514
2026-08-15 15:57:10 -04:00
parent da3725c6de
commit 9b5558dfbc
10 changed files with 348 additions and 2 deletions
@@ -0,0 +1,18 @@
# ForgeFIRM image manifest: source fingerprint of glowforge.ko.
#
# kernel-module-split packages the .ko into a versioned package that the
# recipe's main package only RPROVIDES, so a rootfs file installed here
# would never reach the image. The entry is deployed instead; the image
# collects it from DEPLOY_DIR_IMAGE (forgefirm-image-manifest.bbclass).
inherit forgefirm-manifest deploy
FORGEFIRM_MANIFEST_MODE = "deploy"
python do_deploy() {
import os
entry = forgefirm_manifest_entry(d)
forgefirm_manifest_write(entry, os.path.join(d.getVar('DEPLOYDIR'), 'forgefirm-manifest.d',
d.getVar('PN') + '.json'))
}
do_deploy[vardeps] += "FORGEFIRM_MANIFEST_NAME SRCREV SRC_URI forgefirm_manifest_entry \
forgefirm_manifest_tree forgefirm_manifest_git forgefirm_manifest_write"
addtask deploy after do_install before do_build
@@ -0,0 +1,15 @@
# ForgeFIRM image manifest: kernel identity (forgefirm-image-manifest.bbclass
# collects it from DEPLOY_DIR_IMAGE). The kernel tree is too large to list
# per file and every acceptance test depends on it anyway, so the entry
# carries the pinned revision and the hash of the configuration actually
# built as pseudo-files ("@srcrev", "@config") that the fingerprint globs
# match like any other path. Device-tree sources and config fragments come
# from the BSP layer, which the image manifest hashes by content.
do_deploy:append:glowforge() {
install -d ${DEPLOYDIR}/forgefirm-manifest.d
cfg=$(sha256sum ${B}/.config | cut -d' ' -f1)
printf '{"component":"%s","config_sha256":"%s","files":[["@config","%s"],["@srcrev","%s"]],"linux_version":"%s","pv":"%s","recipe":"%s","source":"%s","srcrev":"%s"}\n' \
"${PN}" "$cfg" "$cfg" "${SRCREV}" "${LINUX_VERSION}" "${PV}" "${PN}" \
"git://github.com/Freescale/linux-fslc.git" "${SRCREV}" \
> ${DEPLOYDIR}/forgefirm-manifest.d/${PN}.json
}