From: "'Felix Moessbauer' via isar-users" <isar-users@googlegroups.com>
To: isar-users@googlegroups.com
Cc: christoph.steiger@siemens.com,
Felix Moessbauer <felix.moessbauer@siemens.com>
Subject: [PATCH 1/6] rootfs: capture apt-state before rootfs cleanup
Date: Mon, 20 Jul 2026 10:13:42 +0200 [thread overview]
Message-ID: <20260720081347.3835974-2-felix.moessbauer@siemens.com> (raw)
In-Reply-To: <20260720081347.3835974-1-felix.moessbauer@siemens.com>
The do_rootfs_postprocess command removes parts of the apt cache which
we need for SBOM generation. On normal builds this is not a problem, as
the SBOM generator runs prior to the rootfs cleanup. However, on partial
rebuilds this can result in incomplete SBOMs which cannot be easily
detected.
This further allows to add more parallelism to the build, as the SBOM
generator can run anytime after do_rootfs_install (not part of this
patch).
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta/classes-recipe/rootfs.bbclass | 21 +++++++++++++++++++++
meta/classes/sbom.bbclass | 10 ++++++----
2 files changed, 27 insertions(+), 4 deletions(-)
diff --git a/meta/classes-recipe/rootfs.bbclass b/meta/classes-recipe/rootfs.bbclass
index e17f711f..16b1aa50 100644
--- a/meta/classes-recipe/rootfs.bbclass
+++ b/meta/classes-recipe/rootfs.bbclass
@@ -42,6 +42,8 @@ ROOTFS_FEATURES:remove:bullseye = "generate-sbom"
ROOTFS_FEATURES:remove:jammy = "generate-sbom"
ROOTFS_FEATURES:remove:focal = "generate-sbom"
+# Capture all information needed for sbom generation
+ROOTFS_APT_STATE = "apt-state.tar.zst"
ROOTFS_APT_ARGS="install --yes -o Debug::pkgProblemResolver=yes"
ROOTFS_CLEAN_FILES="/etc/hostname /etc/resolv.conf"
@@ -414,6 +416,19 @@ rootfs_clear_initrd_symlinks() {
run_privileged rm -f ${ROOTFSDIR}/initrd.img.old
}
+ROOTFS_INSTALL_COMMAND += "${@bb.utils.contains('ROOTFS_FEATURES', 'generate-sbom', 'rootfs_capture_apt_state', '', d)}"
+rootfs_capture_apt_state() {
+ ( cd ${ROOTFSDIR} && find usr/share/doc -name copyright -print0 ) | \
+ tar -cf ${WORKDIR}/${ROOTFS_APT_STATE} --zstd -C ${ROOTFSDIR} \
+ --exclude=var/lib/apt/lists/partial \
+ --exclude=var/lib/apt/lists/lock \
+ --exclude=var/lib/apt/lists/auxfiles \
+ --null -T - \
+ var/lib/apt/lists \
+ var/lib/apt/extended_states \
+ var/lib/dpkg/status
+}
+
do_rootfs_install[root_cleandirs] = "${ROOTFSDIR}"
do_rootfs_install[cleandirs] += "${DEPLOYDIR}"
do_rootfs_install[sstate-inputdirs] = "${DEPLOYDIR}"
@@ -674,6 +689,9 @@ rootfs_install_sstate_prepare() {
tar -C ${WORKDIR}/mnt/rootfs -cpSf rootfs.tar $lopts ${SSTATE_TAR_ATTR_FLAGS} .
umount -q ${WORKDIR}/mnt/rootfs
EOF
+ if [ -f ${WORKDIR}/${ROOTFS_APT_STATE} ]; then
+ cp ${WORKDIR}/${ROOTFS_APT_STATE} .
+ fi
${@ 'sudo chown $(id -u):$(id -g) rootfs.tar' if d.getVar('ISAR_CHROOT_MODE') == 'schroot' else '' }
}
rootfs_install_sstate_prepare[lockfiles] = "${REPO_ISAR_DIR}/isar.lock"
@@ -691,6 +709,9 @@ rootfs_install_sstate_finalize() {
EOF
rm rootfs.tar
fi
+ if [ -f ${ROOTFS_APT_STATE} ]; then
+ mv ${ROOTFS_APT_STATE} ${WORKDIR}/${ROOTFS_APT_STATE}
+ fi
}
python do_rootfs_install_setscene() {
diff --git a/meta/classes/sbom.bbclass b/meta/classes/sbom.bbclass
index 2e6d579f..34efb590 100644
--- a/meta/classes/sbom.bbclass
+++ b/meta/classes/sbom.bbclass
@@ -50,16 +50,18 @@ EOF
}
generate_sbom() {
- run_privileged mkdir -p \
- ${SBOM_CHROOT_LOCAL}/mnt/rootfs \
- ${SBOM_CHROOT_LOCAL}/mnt/deploy-dir
+ run_privileged_heredoc <<'EOF'
+ mkdir -p ${SBOM_CHROOT_LOCAL}/mnt/rootfs \
+ ${SBOM_CHROOT_LOCAL}/mnt/deploy-dir
+ tar -xf ${WORKDIR}/${ROOTFS_APT_STATE} --zstd \
+ -C ${SBOM_CHROOT_LOCAL}/mnt/rootfs
+EOF
TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH})
bwrap \
--unshare-user \
--unshare-pid \
--bind ${SBOM_CHROOT_LOCAL} / \
- --bind ${ROOTFSDIR} /mnt/rootfs \
--bind ${DEPLOY_DIR_SBOM} /mnt/deploy-dir \
-- debsbom -v generate ${SBOM_DEBSBOM_TYPE_ARGS} -r /mnt/rootfs -o /mnt/deploy-dir/'${ROOTFS_PACKAGE_SUFFIX}' \
--distro-name '${SBOM_DISTRO_NAME}' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \
--
2.53.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260720081347.3835974-2-felix.moessbauer%40siemens.com.
next prev parent reply other threads:[~2026-07-20 8:14 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-20 8:13 [PATCH 0/6] Rework SBOM generation 'Felix Moessbauer' via isar-users
2026-07-20 8:13 ` 'Felix Moessbauer' via isar-users [this message]
2026-07-20 8:13 ` [PATCH 2/6] sbom: run generator as task with apt-cache as input 'Felix Moessbauer' via isar-users
2026-07-20 8:13 ` [PATCH 3/6] wic: make dependency to sbom chroot explicit 'Felix Moessbauer' via isar-users
2026-07-20 8:13 ` [PATCH 4/6] sbom: deploy sbom chroot to distro specific file 'Felix Moessbauer' via isar-users
2026-07-20 8:13 ` [PATCH 5/6] sbom: align deploy dir names 'Felix Moessbauer' via isar-users
2026-07-20 8:13 ` [PATCH 6/6] sbom: cache artifact in sstate cache 'Felix Moessbauer' via isar-users
2026-07-28 15:28 ` [PATCH 0/6] Rework SBOM generation Zhihang Wei
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260720081347.3835974-2-felix.moessbauer@siemens.com \
--to=isar-users@googlegroups.com \
--cc=christoph.steiger@siemens.com \
--cc=felix.moessbauer@siemens.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox