public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
From: "'Felix Moessbauer' via isar-users" <isar-users@googlegroups.com>
To: isar-users@googlegroups.com
Cc: cedric.hombourger@siemens.com, jan.kiszka@siemens.com,
	quirin.gylstorff@siemens.com,
	Felix Moessbauer <felix.moessbauer@siemens.com>
Subject: [PATCH 12/13] bootstrap: do not include apt
Date: Fri,  2 Oct 2026 16:49:35 +0200	[thread overview]
Message-ID: <20261002144936.246628-13-felix.moessbauer@siemens.com> (raw)
In-Reply-To: <20261002144936.246628-1-felix.moessbauer@siemens.com>

As we now use the host-apt to operate on the chroot, we don't need apt
inside it. If it is needed (like for the sbuild chroot), we just install
it into the rootfs later on.

Not having apt inside the chroot exposes packaging bugs, assuming that
it (or any of its dependencies) is available. To work around these, we
explicitly install the needed packages on a case-by-case decision.

Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
 meta-isar/conf/distro/raspios-bookworm.conf   |  2 ++
 meta-isar/conf/distro/raspios-bullseye.conf   |  2 ++
 meta-isar/conf/distro/ubuntu-focal.conf       |  3 ++
 .../image-account-extension.bbclass           |  1 +
 meta/classes-recipe/sdk.bbclass               |  5 ++-
 .../isar-mmdebstrap/isar-mmdebstrap.inc       | 32 ++-----------------
 .../sbom-chroot/sbom-chroot.bb                |  2 +-
 .../sbuild-chroot/sbuild-chroot.inc           |  1 +
 8 files changed, 17 insertions(+), 31 deletions(-)

diff --git a/meta-isar/conf/distro/raspios-bookworm.conf b/meta-isar/conf/distro/raspios-bookworm.conf
index 7fc83b0f..92f89c34 100644
--- a/meta-isar/conf/distro/raspios-bookworm.conf
+++ b/meta-isar/conf/distro/raspios-bookworm.conf
@@ -19,6 +19,8 @@ DISTRO_MM_OPTS += "${MMAPTOPT_NOEXPKEYSIGN}"
 
 DISTRO_BOOTSTRAP_KEYS = "http://raspbian.raspberrypi.org/raspbian.public.key;sha256sum=ca59cd4f2bcbc3a1d41ba6815a02a8dc5c175467a59bd87edeac458f4a5345de"
 DISTRO_BOOTSTRAP_KEYS:arm64 = ""
+# workaround for missing depends to apt in raspbian-archive-keyring
+DISTRO_BOOTSTRAP_BASE_PACKAGES:append = " apt gnupg2"
 
 DISTRO_KERNELS ?= "kernel kernel7 kernel7l kernel8"
 
diff --git a/meta-isar/conf/distro/raspios-bullseye.conf b/meta-isar/conf/distro/raspios-bullseye.conf
index a8b59c09..fb0ac423 100644
--- a/meta-isar/conf/distro/raspios-bullseye.conf
+++ b/meta-isar/conf/distro/raspios-bullseye.conf
@@ -20,6 +20,8 @@ DISTRO_MM_OPTS += "${MMAPTOPT_NOEXPKEYSIGN}"
 DISTRO_BOOTSTRAP_KEYS = "http://raspbian.raspberrypi.org/raspbian.public.key;sha256sum=ca59cd4f2bcbc3a1d41ba6815a02a8dc5c175467a59bd87edeac458f4a5345de"
 DISTRO_BOOTSTRAP_KEYS:arm64 = ""
 DISTRO_BOOTSTRAP_BASE_PACKAGES:append = " usrmerge"
+# workaround for missing depends to apt in raspbian-archive-keyring
+DISTRO_BOOTSTRAP_BASE_PACKAGES:append = " apt gnupg2"
 
 DISTRO_KERNELS ?= "kernel kernel7 kernel7l kernel8"
 
diff --git a/meta-isar/conf/distro/ubuntu-focal.conf b/meta-isar/conf/distro/ubuntu-focal.conf
index 155644c1..b6c3e442 100644
--- a/meta-isar/conf/distro/ubuntu-focal.conf
+++ b/meta-isar/conf/distro/ubuntu-focal.conf
@@ -12,3 +12,6 @@ DISTRO_GCC = "9"
 DEBIAN_COMPAT = "12"
 
 DEBIAN_STANDARDS_VERSION ?= "4.5.0"
+
+# workaround for missing depends in /usr/share/initramfs-tools/hooks/fixrtc
+IMAGE_PREINSTALL:append = " e2fsprogs"
diff --git a/meta/classes-recipe/image-account-extension.bbclass b/meta/classes-recipe/image-account-extension.bbclass
index dd70f2a3..8c7a3270 100644
--- a/meta/classes-recipe/image-account-extension.bbclass
+++ b/meta/classes-recipe/image-account-extension.bbclass
@@ -140,6 +140,7 @@ def image_create_users(d: "DataSmart") -> None:
             bb.process.run([*chroot, "/usr/bin/passwd", "--expire", entry])
 
 
+ROOTFS_PACKAGES += "passwd"
 ROOTFS_POSTPROCESS_COMMAND += "image_postprocess_accounts"
 image_postprocess_accounts[vardeps] += "USERS GROUPS"
 python image_postprocess_accounts() {
diff --git a/meta/classes-recipe/sdk.bbclass b/meta/classes-recipe/sdk.bbclass
index 543df84b..b2bf01ed 100644
--- a/meta/classes-recipe/sdk.bbclass
+++ b/meta/classes-recipe/sdk.bbclass
@@ -42,7 +42,10 @@ SDK_PREINSTALL += " \
     apt \
     automake \
     devscripts \
-    equivs"
+    equivs \
+    apt \
+    passwd \
+"
 
 # rootfs/image overrides for the SDK
 ROOTFS_ARCH:class-sdk = "${HOST_ARCH}"
diff --git a/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc b/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
index 6135da4f..103d03bf 100644
--- a/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
+++ b/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
@@ -9,7 +9,7 @@ inherit bootstrap
 inherit compat
 inherit deb-dl-dir
 
-DISTRO_BOOTSTRAP_BASE_PACKAGES += "locales apt"
+DISTRO_BOOTSTRAP_BASE_PACKAGES += "locales"
 DISTRO_BOOTSTRAP_BASE_PACKAGES:append:https-support = " ca-certificates"
 
 BOOTSTRAP_TMPDIR = "${WORKDIR}/tempdir"
@@ -150,7 +150,7 @@ do_bootstrap() {
             bbfatal "${DISTRO_ARCH} does not have a compat arch"
         fi
     fi
-    bootstrap_args="--verbose --variant=minbase --include=${@','.join(d.getVar('DISTRO_BOOTSTRAP_BASE_PACKAGES').split())}"
+    bootstrap_args="--verbose --variant=essential --include=${@','.join(d.getVar('DISTRO_BOOTSTRAP_BASE_PACKAGES').split())}"
     if [ -f "${DISTRO_BOOTSTRAP_KEYRING}" ]; then
         bootstrap_args="$bootstrap_args --keyring=${DISTRO_BOOTSTRAP_KEYRING}"
         cp "${DISTRO_BOOTSTRAP_KEYRING}" "${WORKDIR}/trusted.gpg.d/"
@@ -178,22 +178,7 @@ do_bootstrap() {
         syncout='echo skip sync-out'
         extra_setup="mount --bind '${REPO_BASE_DIR}' $base_apt_tmp"
         extra_extract="$syncout"
-        # save mmdebstrap tempdir for cleanup
-        extra_essential="mkdir -p \$1/$base_apt_tmp && \
-                         echo \$1 > ${WORKDIR}/mmtmpdir && \
-                         mount -o bind,private '${REPO_BASE_DIR}' \$1/$base_apt_tmp"
-        # replace base-apt mount in tmp with /base-apt mount
-        extra_customize="sed -i \"s|copy://$base_apt_tmp|file:///base-apt|g\" \
-                             \$1/etc/apt/sources.list.d/*.list && \
-                         mkdir -p \$1/base-apt && \
-                         mount -o bind,private '${REPO_BASE_DIR}' \$1/base-apt && \
-                         chroot \$1 apt-get update -y \
-                                -o APT::Update::Error-Mode=any \
-                                ${@'-o APT::Sandbox::User=root' if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''} && \
-                         chroot \$1 apt-get install -y dpkg && \
-                         umount \$1/base-apt && \
-                         umount \$1/$base_apt_tmp && \
-                         umount $base_apt_tmp && rmdir \$1/$base_apt_tmp"
+        extra_customize="$syncout"
     else
         # prepare dl_dir for access from both sides (local and rootfs)
         deb_dl_dir_import "${WORKDIR}/dl_dir" "${BOOTSTRAP_BASE_DISTRO}-${BASE_DISTRO_CODENAME}"
@@ -210,15 +195,6 @@ do_bootstrap() {
                        "${WORKDIR}/dl_dir/var/cache/apt/archives/"'
         extra_setup="$syncin"
         extra_extract="$syncout"
-        # prefetch apt debs because mmdebstrap will clean them on next stage
-        extra_essential='apt-get install apt -y -d \
-                                 -o Dir::State="$1/var/lib/apt" \
-                                 -o Dir::Etc="$1/etc/apt" \
-                                 -o Dir::Cache="$1/var/cache/apt" \
-                                 ${@'-o APT::Sandbox::User=root' if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''} \
-                                 -o Apt::Architecture="${BOOTSTRAP_DISTRO_ARCH}" \
-                                 ${@get_apt_opts(d, '-o')}'
-        extra_essential="$extra_essential && $syncout"
         extra_customize="$syncout"
     fi
 
@@ -255,11 +231,9 @@ do_bootstrap() {
                    --setup-hook='upload "${WORKDIR}/chroot-setup.sh" "/chroot-setup.sh"' \
                    --setup-hook='chmod a+rx "$1/chroot-setup.sh"' \
                    --extract-hook="$extra_extract" \
-                   --essential-hook="$extra_essential" \
                    --customize-hook="$extra_customize" \
                    --customize-hook='sed -i "/en_US.UTF-8 UTF-8/s/^# *//g" "$1/etc/locale.gen"' \
                    --customize-hook='chroot "$1" /usr/sbin/locale-gen' \
-                   --customize-hook='chroot "$1" /usr/bin/apt-get -y clean' \
                    --customize-hook='echo nameserver 127.0.0.1 > "$1"/etc/resolv.conf' \
                    --customize-hook='echo isar > "$1"/etc/hostname' \
                    ${@'--skip=output/dev' if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''} \
diff --git a/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb b/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb
index 4727efe4..2f5450ee 100644
--- a/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb
+++ b/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb
@@ -21,7 +21,7 @@ DEPENDS:append:bookworm = " python3-cyclonedx-lib"
 DEPENDS:append:noble = " python3-cyclonedx-lib"
 DEPENDS += "python3-debsbom python3-spdx-tools"
 
-SBOM_IMAGE_INSTALL = "python3-debsbom python3-spdx-tools python3-cyclonedx-lib"
+SBOM_IMAGE_INSTALL = "python3-debsbom python3-spdx-tools python3-cyclonedx-lib lz4"
 
 ROOTFSDIR = "${WORKDIR}/rootfs"
 ROOTFS_PACKAGES = "${SBOM_IMAGE_INSTALL}"
diff --git a/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc b/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
index ae9e0e76..8414f4b8 100644
--- a/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
+++ b/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
@@ -54,6 +54,7 @@ SBUILD_CHROOT_PREINSTALL_COMMON = " \
     ${@ 'ccache' if bb.utils.to_boolean(d.getVar('USE_CCACHE')) else ''} \
     devscripts \
     equivs \
+    apt \
 "
 
 SBUILD_CHROOT_DIR = "${WORKDIR}/rootfs"
-- 
2.55.0

-- 
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-13-felix.moessbauer%40siemens.com.

  parent reply	other threads:[~2026-10-02 14:50 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 01/13] debianize: services are named after BPN not PN 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 02/13] dpkg-raw: do not leak package variants into debian package 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 03/13] debian templates: name package after BPN instead of PN 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 04/13] linux-distro: provide fake packages for native variant of packages 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 05/13] dpkg-source: let the native package variant own the source package 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 06/13] do not assert on legitimate re-execution of tasks 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 07/13] bitbake: backport cooker: use BB_HASHSERVE_DB_DIR for hash server database location 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 08/13] set default sstate signature handler to OEEquivHash 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 09/13] testsuite: add support to run with bitbake hashserver 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 10/13] isar-sstate: add support to clean hashes from hashequiv server 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 11/13] rootfs: use host apt to install packages into rootfs 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users [this message]
2026-10-02 14:49 ` [PATCH 13/13] bootstrap: do not add ca-certificates 'Felix Moessbauer' via isar-users

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002144936.246628-13-felix.moessbauer@siemens.com \
    --to=isar-users@googlegroups.com \
    --cc=cedric.hombourger@siemens.com \
    --cc=felix.moessbauer@siemens.com \
    --cc=jan.kiszka@siemens.com \
    --cc=quirin.gylstorff@siemens.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox