public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
* [PATCH v3 0/3] Update debsbom tool
@ 2026-09-07 12:39 'Felix Moessbauer' via isar-users
  2026-09-07 12:39 ` [PATCH v3 1/3] imager sbom: simplify invocation of " 'Felix Moessbauer' via isar-users
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-09-07 12:39 UTC (permalink / raw)
  To: isar-users; +Cc: christoph.steiger, Felix Moessbauer

Changes since v2:

- delete leftover recipe for 0.10.1

Changes since v1:

- bump debsbom version to 0.10.2 (which fixes the issues
  found on 0.10.1)

Felix Moessbauer (3):
  imager sbom: simplify invocation of debsbom tool
  debsbom: update to v0.10.2
  rootfs sbom: directly use captured apt state without extraction

 meta/classes-recipe/image-tools-extension.bbclass      |  6 +-----
 meta/classes/sbom.bbclass                              | 10 ++--------
 ...hon3-debsbom_0.8.1.bb => python3-debsbom_0.10.2.bb} |  2 +-
 3 files changed, 4 insertions(+), 14 deletions(-)
 rename meta/recipes-support/python3-debsbom/{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.2.bb} (95%)

-- 
2.55.0

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260907123945.353664-1-felix.moessbauer%40siemens.com.

^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v3 1/3] imager sbom: simplify invocation of debsbom tool
  2026-09-07 12:39 [PATCH v3 0/3] Update debsbom tool 'Felix Moessbauer' via isar-users
@ 2026-09-07 12:39 ` 'Felix Moessbauer' via isar-users
  2026-09-07 12:39 ` [PATCH v3 2/3] debsbom: update to v0.10.2 'Felix Moessbauer' via isar-users
                   ` (2 subsequent siblings)
  3 siblings, 0 replies; 5+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-09-07 12:39 UTC (permalink / raw)
  To: isar-users; +Cc: christoph.steiger, Felix Moessbauer

We don't need to create the output directory upfront, as bwrap
internally does this on bind-mounting. Further, we avoid being extra
verbose to align the debsbom CLI with the other invocations.

Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 meta/classes-recipe/image-tools-extension.bbclass | 6 +-----
 1 file changed, 1 insertion(+), 5 deletions(-)

diff --git a/meta/classes-recipe/image-tools-extension.bbclass b/meta/classes-recipe/image-tools-extension.bbclass
index 8f666444..754db7a6 100644
--- a/meta/classes-recipe/image-tools-extension.bbclass
+++ b/meta/classes-recipe/image-tools-extension.bbclass
@@ -102,10 +102,6 @@ EOAPT
 }
 
 generate_imager_sbom_in_chroot() {
-    run_privileged mkdir -p \
-        ${SBOM_CHROOT_LOCAL}/mnt/rootfs \
-        ${SBOM_CHROOT_LOCAL}/mnt/deploy-dir
-
     TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH})
     sbom_document_uuid="${@d.getVar('SBOM_DOCUMENT_UUID') or generate_document_uuid(d, False)}"
     bwrap \
@@ -114,7 +110,7 @@ generate_imager_sbom_in_chroot() {
         --bind ${SBOM_CHROOT_LOCAL} / \
         --bind $1 /mnt/rootfs \
         --bind ${WORKDIR} /mnt/deploy-dir \
-        -- debsbom -vv generate ${SBOM_DEBSBOM_TYPE_ARGS} \
+        -- debsbom -v generate ${SBOM_DEBSBOM_TYPE_ARGS} \
             --from-pkglist -r /mnt/rootfs -o /mnt/deploy-dir/imager \
             --distro-name '${SBOM_DISTRO_NAME}-Imager' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \
             --distro-version '${SBOM_DISTRO_VERSION}' --distro-arch '${DISTRO_ARCH}' \
-- 
2.55.0

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260907123945.353664-2-felix.moessbauer%40siemens.com.

^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v3 2/3] debsbom: update to v0.10.2
  2026-09-07 12:39 [PATCH v3 0/3] Update debsbom tool 'Felix Moessbauer' via isar-users
  2026-09-07 12:39 ` [PATCH v3 1/3] imager sbom: simplify invocation of " 'Felix Moessbauer' via isar-users
@ 2026-09-07 12:39 ` 'Felix Moessbauer' via isar-users
  2026-09-07 12:39 ` [PATCH v3 3/3] rootfs sbom: directly use captured apt state without extraction 'Felix Moessbauer' via isar-users
  2026-09-08 14:54 ` [PATCH v3 0/3] Update debsbom tool Zhihang Wei
  3 siblings, 0 replies; 5+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-09-07 12:39 UTC (permalink / raw)
  To: isar-users; +Cc: christoph.steiger, Felix Moessbauer

This brings a couple of bugfixes, as well as support to read the package
data from a tar file.

Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 .../{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.2.bb}     | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
 rename meta/recipes-support/python3-debsbom/{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.2.bb} (95%)

diff --git a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
similarity index 95%
rename from meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
rename to meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
index 7fc9a8eb..1aec1369 100644
--- a/meta/recipes-support/python3-debsbom/python3-debsbom_0.8.1.bb
+++ b/meta/recipes-support/python3-debsbom/python3-debsbom_0.10.2.bb
@@ -35,7 +35,7 @@ SRC_URI = "git://github.com/siemens/debsbom.git;protocol=https;branch=main; \
            file://rules \
            file://0001-Use-old-license-description-in-pyproject.toml.patch \
            "
-SRCREV = "a76d4e784f84e73b98d2bbeadd28c602a8c13708"
+SRCREV = "9b5a5d6be05f1207356223f88b3080bd72722b9f"
 
 do_prepare_build[cleandirs] += "${S}/debian"
 do_prepare_build() {
-- 
2.55.0

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260907123945.353664-3-felix.moessbauer%40siemens.com.

^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH v3 3/3] rootfs sbom: directly use captured apt state without extraction
  2026-09-07 12:39 [PATCH v3 0/3] Update debsbom tool 'Felix Moessbauer' via isar-users
  2026-09-07 12:39 ` [PATCH v3 1/3] imager sbom: simplify invocation of " 'Felix Moessbauer' via isar-users
  2026-09-07 12:39 ` [PATCH v3 2/3] debsbom: update to v0.10.2 'Felix Moessbauer' via isar-users
@ 2026-09-07 12:39 ` 'Felix Moessbauer' via isar-users
  2026-09-08 14:54 ` [PATCH v3 0/3] Update debsbom tool Zhihang Wei
  3 siblings, 0 replies; 5+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-09-07 12:39 UTC (permalink / raw)
  To: isar-users; +Cc: christoph.steiger, Felix Moessbauer

Since version 0.10 debsbom is capable of reading the apt state from a
tarball instead of an extracted rootfs. By that, we can remove the
manual extraction of the apt state and instead directly pass the tarball
to debsbom.

Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 meta/classes/sbom.bbclass | 10 ++--------
 1 file changed, 2 insertions(+), 8 deletions(-)

diff --git a/meta/classes/sbom.bbclass b/meta/classes/sbom.bbclass
index b2e8aff6..43b8a71e 100644
--- a/meta/classes/sbom.bbclass
+++ b/meta/classes/sbom.bbclass
@@ -51,20 +51,14 @@ EOF
 }
 
 generate_sbom() {
-    run_privileged_heredoc <<'EOF'
-        mkdir -p ${SBOM_CHROOT_LOCAL}/mnt/rootfs \
-                 ${SBOM_CHROOT_LOCAL}/mnt/deploy-dir
-        tar -xf ${WORKDIR}/${ROOTFS_APT_STATE} --zstd \
-            -C ${SBOM_CHROOT_LOCAL}/mnt/rootfs
-EOF
-
     TIMESTAMP=$(date --iso-8601=s -d @${SOURCE_DATE_EPOCH})
+    unzstd < ${WORKDIR}/${ROOTFS_APT_STATE} | \
     bwrap \
         --unshare-user \
         --unshare-pid \
         --bind ${SBOM_CHROOT_LOCAL} / \
         --bind ${SBOM_LOCAL_DEPLOYDIR} /mnt/deploy-dir \
-        -- debsbom -v generate ${SBOM_DEBSBOM_TYPE_ARGS} -r /mnt/rootfs -o /mnt/deploy-dir/'${ROOTFS_PACKAGE_SUFFIX}' \
+        -- debsbom -v generate ${SBOM_DEBSBOM_TYPE_ARGS} -r - -o /mnt/deploy-dir/'${ROOTFS_PACKAGE_SUFFIX}' \
             --distro-name '${SBOM_DISTRO_NAME}' --distro-supplier '${SBOM_DISTRO_SUPPLIER}' \
             --distro-version '${SBOM_DISTRO_VERSION}' --distro-arch '${DISTRO_ARCH}' \
             --base-distro-vendor '${SBOM_BASE_DISTRO_VENDOR}' \
-- 
2.55.0

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20260907123945.353664-4-felix.moessbauer%40siemens.com.

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH v3 0/3] Update debsbom tool
  2026-09-07 12:39 [PATCH v3 0/3] Update debsbom tool 'Felix Moessbauer' via isar-users
                   ` (2 preceding siblings ...)
  2026-09-07 12:39 ` [PATCH v3 3/3] rootfs sbom: directly use captured apt state without extraction 'Felix Moessbauer' via isar-users
@ 2026-09-08 14:54 ` Zhihang Wei
  3 siblings, 0 replies; 5+ messages in thread
From: Zhihang Wei @ 2026-09-08 14:54 UTC (permalink / raw)
  To: Felix Moessbauer, isar-users; +Cc: christoph.steiger


On 9/7/26 14:39, 'Felix Moessbauer' via isar-users wrote:
> Changes since v2:
>
> - delete leftover recipe for 0.10.1
>
> Changes since v1:
>
> - bump debsbom version to 0.10.2 (which fixes the issues
>    found on 0.10.1)
>
> Felix Moessbauer (3):
>    imager sbom: simplify invocation of debsbom tool
>    debsbom: update to v0.10.2
>    rootfs sbom: directly use captured apt state without extraction
>
>   meta/classes-recipe/image-tools-extension.bbclass      |  6 +-----
>   meta/classes/sbom.bbclass                              | 10 ++--------
>   ...hon3-debsbom_0.8.1.bb => python3-debsbom_0.10.2.bb} |  2 +-
>   3 files changed, 4 insertions(+), 14 deletions(-)
>   rename meta/recipes-support/python3-debsbom/{python3-debsbom_0.8.1.bb => python3-debsbom_0.10.2.bb} (95%)
>
Hi Felix,

The test_sbom_rootfs_generate test failed on CI. It can pass in rootless 
mode but failed in root mode.

Failed task: 
mc:qemuamd64-trixie:/isar/build/../meta-test/recipes-core/images/isar-rootfs-ci.bb:do_generate_sbom
Relevant task log:
DEBUG: Executing python function sstate_task_prefunc
DEBUG: Python function sstate_task_prefunc finished
DEBUG: Executing python function do_generate_sbom
DEBUG: Executing shell function prepare_sbom_chroot
DEBUG: Shell function prepare_sbom_chroot finished
DEBUG: Executing shell function generate_sbom
bwrap: Can't mkdir /mnt/deploy-dir: Permission denied
WARNING: exit code 1 from a shell command.
DEBUG: Executing shell function cleanup_sbom_chroot
DEBUG: Shell function cleanup_sbom_chroot finished
DEBUG: Python function do_generate_sbom finished

To recreate the issue, run:
scripts/run-tests.sh testsuite/citest.py:test_sbom_rootfs_generate

Zhihang

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/58e76df6-6753-4e18-918f-63e963d81321%40ilbers.de.

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-08 14:54 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-07 12:39 [PATCH v3 0/3] Update debsbom tool 'Felix Moessbauer' via isar-users
2026-09-07 12:39 ` [PATCH v3 1/3] imager sbom: simplify invocation of " 'Felix Moessbauer' via isar-users
2026-09-07 12:39 ` [PATCH v3 2/3] debsbom: update to v0.10.2 'Felix Moessbauer' via isar-users
2026-09-07 12:39 ` [PATCH v3 3/3] rootfs sbom: directly use captured apt state without extraction 'Felix Moessbauer' via isar-users
2026-09-08 14:54 ` [PATCH v3 0/3] Update debsbom tool Zhihang Wei

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox