Files
forgefirm/meta-forgefirm/conf/distro/forgefirm.conf
T
ScottW514 9711a7fa06 The audit's deferred findings: the checksum exclude, the resume-lead drill, the record
B-16: BB_SIGNATURE_LOCAL_DIRS_EXCLUDE in the distro conf names __pycache__
and .pytest_cache, so a workstation's bytecode caches never enter a
file:// checksum (proven in the build VM: a cache under the package leaves
the fetch task alone, a source change reruns it).

kernel.resume-lead: two phases behind one takeover at a 1 kHz tick. E, a
resume whose lead is longer than the data ends at end-of-data within a few
ticks (a lost end-of-data would show as 255 ms). L, a 1000-byte lead over
FIRE bits with the latch unlocked and the chain unarmed keeps the FIRE
line low through the lead and drives it from the waypoint byte on. The
bench proof for the module's K-4 and K-8 fixes; the catalog counts 55
tests, 0 uncovered.

BRINGUP items 9 and 11 and the CAMPAIGN-LOG entry record the batch and the
campaign rule: no campaign until every audit finding is on one image.
2026-09-02 20:03:22 -04:00

36 lines
1.7 KiB
Plaintext

require conf/distro/include/fslc-base.inc
DISTRO = "forgefirm"
DISTRO_NAME = "OpenGlow/ForgeFIRM"
DISTRO_VERSION = "0.0.0"
DISTRO_FEATURES:remove = " \
3g alsa avahi bluetooth bluez5 ext2 irda nfc nfs pci pcmcia \
pulseaudio vulkan wayland x11 zeroconf "
# opengl stays: forgectrl's camera demosaic runs as GLES2 fragment
# shaders on the GC880 (etnaviv), reached through surfaceless EGL with
# no display stack. Mesa is trimmed to exactly that: the etnaviv
# gallium driver, GLES/EGL/GBM, no GLX, no X11/Wayland platforms
# (both remain removed above), so the cost is the libraries and the one
# driver, not a graphics stack.
PACKAGECONFIG:pn-mesa = "opengl gles egl gbm gallium etnaviv"
# udev's hardware database is USB and PCI vendor/product identities (7.7 MB);
# the board has neither bus.
BAD_RECOMMENDATIONS += "eudev-hwdb"
# System logger: rsyslog replaces busybox syslogd/klogd. Every ForgeFIRM
# process logs through it and it is the only log writer (one directory
# per logger under /data/log/forgefirm; per-logger levels and the remote
# target come from the machine settings). Trimmed to what the image uses:
# the local socket and kernel inputs, file output, plain UDP/TCP
# forwarding, and rainerscript filters - no TLS, database, HTTP, or
# signing modules (rootfs must fit the 200 MiB factory slot).
VIRTUAL-RUNTIME_base-utils-syslog = "rsyslog"
PACKAGECONFIG:pn-rsyslog = "rsyslogd rsyslogrt klog inet regexp"
# Local (file://) source checksums leave out a workstation's Python bytecode
# caches: the forgetest recipe fetches its package directory whole, and a
# host test run must not move a task hash without a source change.
BB_SIGNATURE_LOCAL_DIRS_EXCLUDE = "CVS .bzr .git .hg .osc .p4 .repo .svn __pycache__ .pytest_cache"