Files
forgefirm/kas/forgefirm-glowforge.yml
T
ScottW514 e9443a60ef Keep debug-tweaks out of release images; harden the installer
- Move the passwordless-root debug-tweaks image feature out of the
  shared kas config into forgefirm-image-dev.bb, so the release
  forgefirm-image built from the same config is not passwordless-root.
  release.sh gains a gate that reads the built rootfs /etc/shadow and
  fails on an empty root password, plus a config-level guard that
  debug-tweaks is not present in the resolved kas dump. (B-1)
- The installer copies ffboot out of the signature-verified new rootfs
  it already mounts, instead of fetching and executing it from a mutable
  GitHub raw ref. (B-2)
- Record audit remediation Phase 2 (GATE B) status in BRINGUP.md,
  including the bench pass still required to close the gate.
2026-08-14 16:20:02 -04:00

133 lines
5.3 KiB
YAML

# ============================================================================
# ForgeFIRM — kas build configuration (factory Glowforge control board)
# ============================================================================
# The forgefirm repo is the BASE: it controls the build, the output firmware
# images land here (build/tmp/deploy/images/glowforge/), and the build/install
# docs live here (BUILD.md, INSTALL.md, SERIAL.md, kas/README.md).
#
# Target : Yocto Scarthgap (5.0 LTS) + linux-fslc 6.12 (mainline LTS)
# Machine: glowforge (i.MX6 Solo SOM inside Basic/Plus/Pro)
# Distro : forgefirm
#
# kas generates bblayers.conf and local.conf.
#
# Run from the forgefirm repo root so outputs land inside it:
# cd forgefirm
# kas build kas/forgefirm-glowforge.yml # fetch layers + full build
# kas shell kas/forgefirm-glowforge.yml # interactive bitbake env
# kas dump kas/forgefirm-glowforge.yml # show resolved config
#
# Reproducible pins (after first checkout):
# kas lock kas/forgefirm-glowforge.yml # writes kas/forgefirm-glowforge.lock.yml
# ============================================================================
header:
version: 14
machine: glowforge
distro: forgefirm
target: forgefirm-image
# kas uses KAS_WORK_DIR (the dir you run kas from = the forgefirm repo root).
# Upstream layers are cloned into ./layers/, the build runs in ./build/, and
# caches go in ./downloads + ./sstate-cache — all gitignored, all inside forgefirm.
repos:
# --- This repo (forgefirm) — auto-detected, no url/path needed -------------
forgefirm:
layers:
meta-forgefirm:
# --- Upstream layers (cloned + pinned to the scarthgap branch by kas) ------
poky:
url: https://git.yoctoproject.org/poky.git
branch: scarthgap
path: layers/poky
layers:
meta:
meta-poky:
meta-openembedded:
url: https://github.com/openembedded/meta-openembedded.git
branch: scarthgap
path: layers/meta-openembedded
layers:
meta-oe:
meta-python:
meta-networking:
meta-freescale:
url: https://github.com/Freescale/meta-freescale.git
branch: scarthgap
path: layers/meta-freescale
layers:
.:
meta-freescale-distro:
# Provides conf/distro/include/fslc-base.inc, required by the forgefirm distro.
url: https://github.com/Freescale/meta-freescale-distro.git
branch: scarthgap
path: layers/meta-freescale-distro
layers:
.:
# --- meta-openglow — Glowforge BSP layers ---------------------------------
# ACTIVE DEVELOPMENT: referenced as a local sibling checkout (no url => kas
# performs no git ops, so the scarthgap-migration edits we're making are what
# gets built). The kernel-module-glowforge sources are NOT a layer; they are
# pulled by the kernel-module-glowforge.bb recipe's SRC_URI, so kas does not
# manage them here.
meta-openglow:
path: ../meta-openglow
layers:
meta-openglow-core:
meta-glowforge-bsp:
# meta-openglow-bsp (separate OpenGlow_std board) intentionally excluded.
#
# FUTURE — flip to this pinned-remote block at release time (gated on
# active BSP development settling — see kas/README.md "Push & release order".
# When flipping, also drop meta-openglow's kernel-module-glowforge.bbappend
# (externalsrc to the local sibling) so a fresh clone is self-contained; its
# perl-native DEPENDS is already carried in the base recipe):
# meta-openglow:
# url: https://github.com/ScottW514/meta-openglow.git
# branch: scarthgap # pin via kas lock / a tag at release
# path: layers/meta-openglow
# layers:
# meta-openglow-core:
# meta-glowforge-bsp:
# ----------------------------------------------------------------------------
# local.conf additions
# ----------------------------------------------------------------------------
local_conf_header:
# Accept the NXP/Freescale firmware EULA — required to unpack firmware-imx
# (i.MX SDMA/VPU firmware blobs) pulled in by the i.MX6 BSP. ForgeFIRM targets
# the factory i.MX6 Glowforge board, so this firmware is intrinsic to the image.
eula: |
ACCEPT_FSL_EULA = "1"
# The kernel defaults to linux-fslc 6.12 in conf/machine/glowforge.conf
# (with the factory drivers forward-ported — EPIT/SDMA/OV5648/glowforge.ko —
# see kas/README.md backlog #2). This explicit pin is redundant but harmless.
kernel: |
PREFERRED_PROVIDER_virtual/kernel = "linux-fslc"
PREFERRED_VERSION_linux-fslc = "6.12%"
# NOTE: debug-tweaks (passwordless root) is deliberately NOT set here. It
# would apply to every target built from this config, including the release
# forgefirm-image. It lives in forgefirm-image-dev.bb's IMAGE_FEATURES so a
# single build yields a hardened release image and a debug dev image.
# release.sh gates the release rootfs against a passwordless root entry.
build-tweaks: |
# Parallelism for the 12-core / 16 GB WSL2 VM. (The earlier mid-build deaths
# were the mirrored-networking vsock relay, not memory — see .wslconfig — so
# this can comfortably use more of the VM.)
BB_NUMBER_THREADS = "8"
PARALLEL_MAKE = "-j 8"
# Caches kept inside the forgefirm repo (gitignored):
DL_DIR ?= "${TOPDIR}/../downloads"
SSTATE_DIR ?= "${TOPDIR}/../sstate-cache"