mirror of
https://github.com/openglow-org/forgefirm.git
synced 2026-09-28 09:11:11 -07:00
- Move the passwordless-root debug-tweaks image feature out of the shared kas config into forgefirm-image-dev.bb, so the release forgefirm-image built from the same config is not passwordless-root. release.sh gains a gate that reads the built rootfs /etc/shadow and fails on an empty root password, plus a config-level guard that debug-tweaks is not present in the resolved kas dump. (B-1) - The installer copies ffboot out of the signature-verified new rootfs it already mounts, instead of fetching and executing it from a mutable GitHub raw ref. (B-2) - Record audit remediation Phase 2 (GATE B) status in BRINGUP.md, including the bench pass still required to close the gate.
27 lines
876 B
BlitzBasic
27 lines
876 B
BlitzBasic
require forgefirm-image.bb
|
|
|
|
DESCRIPTION = "OpenGlow/ForgeFIRM development image for Glowforge"
|
|
|
|
# Strict superset of forgefirm-image: everything the main image ships, plus
|
|
# debug tooling.
|
|
IMAGE_INSTALL += " \
|
|
forgectrl \
|
|
"
|
|
|
|
# debug-tweaks (passwordless root, root SSH login) belongs ONLY to the dev
|
|
# image - never the release image. It lives here, not in the shared kas
|
|
# local.conf, so the release forgefirm-image cannot inherit it.
|
|
IMAGE_FEATURES += " \
|
|
tools-debug \
|
|
debug-tweaks \
|
|
"
|
|
|
|
# Dev images boot from SD, never from a 200 MiB eMMC slot: lift the slot
|
|
# ceiling and give the filesystem generous working space instead.
|
|
IMAGE_ROOTFS_MAXSIZE = ""
|
|
IMAGE_ROOTFS_EXTRA_SPACE = "262144"
|
|
|
|
# Dev builds identify by build timestamp (matches the artifact name),
|
|
# tagged so a bench machine is never mistaken for a release.
|
|
FORGEFIRM_VERSION_STRING = "${DATETIME} (dev)"
|