* [PATCH 01/13] debianize: services are named after BPN not PN
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 02/13] dpkg-raw: do not leak package variants into debian package 'Felix Moessbauer' via isar-users
` (11 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
In 09f4698a logic was added to automatically copy triggers and service
files into the debian folder so that they are picked up by debhelper.
However, the services were only looked up under their
${PN}.{service,trigger}, which breaks on variant builds like -native and
-compat.
As the package variant suffix is a bitbake only thing, it must not end
up in the names of the services (neither on lookup, nor on copy-in),
as the debian package is named ${BPN} and the entries must match.
Along that, we fix an incorrect tabs vs. spaces indentation.
Fixes: 09f4698a ("debianize: add support for systemd unit files")
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
.../recipes-bsp/optee-examples/files/debian/control.tmpl | 2 +-
meta/classes-recipe/debianize.bbclass | 6 +++---
meta/recipes-bsp/optee-client/files/debian/control.tmpl | 2 +-
3 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl b/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl
index 7533c34a..8b8e4eef 100644
--- a/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl
+++ b/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl
@@ -1,4 +1,4 @@
-Source: ${PN}
+Source: ${BPN}
Section: admin
Priority: optional
Standards-Version: ${DEBIAN_STANDARDS_VERSION}
diff --git a/meta/classes-recipe/debianize.bbclass b/meta/classes-recipe/debianize.bbclass
index 6f6141b0..e483a52d 100644
--- a/meta/classes-recipe/debianize.bbclass
+++ b/meta/classes-recipe/debianize.bbclass
@@ -206,10 +206,10 @@ deb_debianize() {
for f in ${dh_installdeb_handled} \
${dh_installsystemd_handled} \
${dh_installsystemduser_handled} \
- ${dh_installtmpfiles_handled}
+ ${dh_installtmpfiles_handled}
do
- if [ -f ${WORKDIR}/${PN}${f} ]; then
- install -v -m 644 ${WORKDIR}/${PN}${f} ${S}/debian/
+ if [ -f ${WORKDIR}/${BPN}${f} ]; then
+ install -v -m 644 ${WORKDIR}/${BPN}${f} ${S}/debian/
fi
done
}
diff --git a/meta/recipes-bsp/optee-client/files/debian/control.tmpl b/meta/recipes-bsp/optee-client/files/debian/control.tmpl
index e3864407..0887c358 100644
--- a/meta/recipes-bsp/optee-client/files/debian/control.tmpl
+++ b/meta/recipes-bsp/optee-client/files/debian/control.tmpl
@@ -1,4 +1,4 @@
-Source: ${PN}
+Source: ${BPN}
Priority: optional
Maintainer: Unknown maintainer <unknown@example.com>
Build-Depends: debhelper-compat (= ${DEBIAN_COMPAT}),
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-2-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 02/13] dpkg-raw: do not leak package variants into debian package
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 01/13] debianize: services are named after BPN not PN 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 03/13] debian templates: name package after BPN instead of PN 'Felix Moessbauer' via isar-users
` (10 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
When generating a dpkg-raw package from a -native or -compat variant,
the wrong install file is looked up (${PN}.install vs. ${BPN}.install)
and the root dir name of the generated source package is wrong
(${PN}-${PV} vs. ${BPN}-${PV}). By that, sbuild does not consider the
files in the debian dir and silently generates an empty package.
As dpkg-raw packages usually only were generated in its natural form
(PN = BPN), this bug remained unnoticed for a long time.
Fixes: c63bb31b ("add multiarch support")
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta/classes-recipe/dpkg-raw.bbclass | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/meta/classes-recipe/dpkg-raw.bbclass b/meta/classes-recipe/dpkg-raw.bbclass
index 7860389e..97207fff 100644
--- a/meta/classes-recipe/dpkg-raw.bbclass
+++ b/meta/classes-recipe/dpkg-raw.bbclass
@@ -9,6 +9,7 @@ inherit dpkg
# adding excluded files, e.g. *.so to a package.
DPKG_SOURCE_EXTRA_ARGS = ""
+S = "${WORKDIR}/${BPN}-${PV}"
D = "${S}/image"
# Default to creating a binary-indep package
@@ -27,7 +28,7 @@ do_prepare_build[cleandirs] += "${S}/debian"
do_prepare_build() {
cd ${D}
find . -maxdepth 1 ! -name .. -and ! -name . -and ! -name debian | \
- sed 's:^./::' | sort > ${S}/debian/${PN}.install
+ sed 's:^./::' | sort > ${S}/debian/${BPN}.install
deb_debianize
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-3-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 03/13] debian templates: name package after BPN instead of PN
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 01/13] debianize: services are named after BPN not PN 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 02/13] dpkg-raw: do not leak package variants into debian package 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 04/13] linux-distro: provide fake packages for native variant of packages 'Felix Moessbauer' via isar-users
` (9 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
The package variants are are bitbake-only thing but must not affect the
name of the generated packages. By that, all control files must use
Source: ${BPN} instead of Source: ${PN} (and alike for the binary
package).
We fix this for the remaining packages that don't use debianize but
provide their own template.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
.../optee-examples/files/debian/control.tmpl | 24 ++++++-------
.../optee-examples-stm32mp15x_3.21.0.bb | 36 +++++++++----------
meta/classes-recipe/dracut-module.bbclass | 2 +-
meta/classes-recipe/linux-module.bbclass | 4 +--
.../optee-ftpm/files/debian/control.tmpl | 4 +--
.../linux-module/files/debian/control.tmpl | 4 +--
.../linux-module/files/debian/rules.tmpl | 2 +-
7 files changed, 38 insertions(+), 38 deletions(-)
diff --git a/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl b/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl
index 8b8e4eef..ff537e46 100644
--- a/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl
+++ b/meta-isar/recipes-bsp/optee-examples/files/debian/control.tmpl
@@ -6,7 +6,7 @@ Build-Depends: debhelper-compat (= ${DEBIAN_COMPAT}), ${DEBIAN_BUILD_DEPENDS}
Maintainer: Isar project <isar-users@googlegroups.com>
Rules-Requires-Root: no
-Package: ${PN}-acipher-ta
+Package: ${BPN}-acipher-ta
Architecture: ${DISTRO_ARCH}
Description: OP-TEE Trusted Application example - acipher
Generates an RSA key pair of specified size and encrypts a supplied string with
@@ -14,7 +14,7 @@ Description: OP-TEE Trusted Application example - acipher
.
UUID: a734eed9-d6a1-4244-aa50-7c99719e7b7b
-Package: ${PN}-acipher-host
+Package: ${BPN}-acipher-host
Architecture: ${DISTRO_ARCH}
Depends: libteec1, tee-supplicant,
${misc:Depends}
@@ -24,7 +24,7 @@ Description: OP-TEE Trusted Application example - acipher (host application)
.
UUID: a734eed9-d6a1-4244-aa50-7c99719e7b7b
-Package: ${PN}-aes-ta
+Package: ${BPN}-aes-ta
Architecture: ${DISTRO_ARCH}
Description: OP-TEE Trusted Application example - aes
Runs an AES encryption and decryption from a TA using the GlobalPlatform TEE
@@ -33,7 +33,7 @@ Description: OP-TEE Trusted Application example - aes
.
UUID: 5dbac793-f574-4871-8ad3-04331ec17f24
-Package: ${PN}-aes-host
+Package: ${BPN}-aes-host
Architecture: ${DISTRO_ARCH}
Depends: libteec1, tee-supplicant,
${misc:Depends}
@@ -44,7 +44,7 @@ Description: OP-TEE Trusted Application example - aes (host application)
.
UUID: 5dbac793-f574-4871-8ad3-04331ec17f24
-Package: ${PN}-hello-world-ta
+Package: ${BPN}-hello-world-ta
Architecture: ${DISTRO_ARCH}
Description: OP-TEE Trusted Application example - hello_world
This is a very simple Trusted Application to answer a hello command and
@@ -52,7 +52,7 @@ Description: OP-TEE Trusted Application example - hello_world
.
UUID: 8aaaf200-2450-11e4-abe2-0002a5d5c51b
-Package: ${PN}-hello-world-host
+Package: ${BPN}-hello-world-host
Architecture: ${DISTRO_ARCH}
Depends: libteec1, tee-supplicant,
${misc:Depends}
@@ -62,14 +62,14 @@ Description: OP-TEE Trusted Application example - hello_world (host application)
.
UUID: 8aaaf200-2450-11e4-abe2-0002a5d5c51b
-Package: ${PN}-hotp-ta
+Package: ${BPN}-hotp-ta
Architecture: ${DISTRO_ARCH}
Description: OP-TEE Trusted Application example - hotp
HMAC based One Time Password in OP-TEE.
.
UUID: 484d4143-2d53-4841-3120-4a6f636b6542
-Package: ${PN}-hotp-host
+Package: ${BPN}-hotp-host
Architecture: ${DISTRO_ARCH}
Depends: libteec1, tee-supplicant,
${misc:Depends}
@@ -78,14 +78,14 @@ Description: OP-TEE Trusted Application example - hotp (host application)
.
UUID: 484d4143-2d53-4841-3120-4a6f636b6542
-Package: ${PN}-random-ta
+Package: ${BPN}-random-ta
Architecture: ${DISTRO_ARCH}
Description: OP-TEE Trusted Application example - random
Generates a random UUID using capabilities of TEE API (TEE_GenerateRandom()).
.
UUID: b6c53aba-9669-4668-a7f2-205629d00f86
-Package: ${PN}-random-host
+Package: ${BPN}-random-host
Architecture: ${DISTRO_ARCH}
Depends: libteec1, tee-supplicant,
${misc:Depends}
@@ -94,7 +94,7 @@ Description: OP-TEE Trusted Application example - random (host application)
.
UUID: b6c53aba-9669-4668-a7f2-205629d00f86
-Package: ${PN}-secure-storage-ta
+Package: ${BPN}-secure-storage-ta
Architecture: ${DISTRO_ARCH}
Description: OP-TEE Trusted Application example - secure_storage
A Trusted Application to read/write raw data into the OP-TEE secure storage
@@ -102,7 +102,7 @@ Description: OP-TEE Trusted Application example - secure_storage
.
UUID: f4e750bb-1437-4fbf-8785-8d3580c34994
-Package: ${PN}-secure-storage-host
+Package: ${BPN}-secure-storage-host
Architecture: ${DISTRO_ARCH}
Depends: libteec1, tee-supplicant,
${misc:Depends}
diff --git a/meta-isar/recipes-bsp/optee-examples/optee-examples-stm32mp15x_3.21.0.bb b/meta-isar/recipes-bsp/optee-examples/optee-examples-stm32mp15x_3.21.0.bb
index cbe2a635..f35df17b 100644
--- a/meta-isar/recipes-bsp/optee-examples/optee-examples-stm32mp15x_3.21.0.bb
+++ b/meta-isar/recipes-bsp/optee-examples/optee-examples-stm32mp15x_3.21.0.bb
@@ -53,51 +53,51 @@ do_prepare_build() {
# acipher.install
echo "acipher/ta/a734eed9-d6a1-4244-aa50-7c99719e7b7b.ta /usr/lib/optee-os/${OPTEE_NAME}/ta" > \
- ${S}/debian/${PN}-acipher-ta.install
+ ${S}/debian/${BPN}-acipher-ta.install
echo "acipher/ta/a734eed9-d6a1-4244-aa50-7c99719e7b7b.stripped.elf /usr/lib/optee-os/${OPTEE_NAME}/ta" >> \
- ${S}/debian/${PN}-acipher-ta.install
+ ${S}/debian/${BPN}-acipher-ta.install
echo "acipher/host/optee_example_acipher /usr/lib/optee-os/${OPTEE_NAME}/ca" > \
- ${S}/debian/${PN}-acipher-host.install
+ ${S}/debian/${BPN}-acipher-host.install
# aes.install
echo "aes/ta/5dbac793-f574-4871-8ad3-04331ec17f24.ta /usr/lib/optee-os/${OPTEE_NAME}/ta" > \
- ${S}/debian/${PN}-aes-ta.install
+ ${S}/debian/${BPN}-aes-ta.install
echo "aes/ta/5dbac793-f574-4871-8ad3-04331ec17f24.stripped.elf /usr/lib/optee-os/${OPTEE_NAME}/ta" >> \
- ${S}/debian/${PN}-aes-ta.install
+ ${S}/debian/${BPN}-aes-ta.install
echo "aes/host/optee_example_aes /usr/lib/optee-os/${OPTEE_NAME}/ca" > \
- ${S}/debian/${PN}-aes-host.install
+ ${S}/debian/${BPN}-aes-host.install
# hello-world.install
echo "hello_world/ta/8aaaf200-2450-11e4-abe2-0002a5d5c51b.ta /usr/lib/optee-os/${OPTEE_NAME}/ta" > \
- ${S}/debian/${PN}-hello-world-ta.install
+ ${S}/debian/${BPN}-hello-world-ta.install
echo "hello_world/ta/8aaaf200-2450-11e4-abe2-0002a5d5c51b.stripped.elf /usr/lib/optee-os/${OPTEE_NAME}/ta" >> \
- ${S}/debian/${PN}-hello-world-ta.install
+ ${S}/debian/${BPN}-hello-world-ta.install
echo "hello_world/host/optee_example_hello_world /usr/lib/optee-os/${OPTEE_NAME}/ca" > \
- ${S}/debian/${PN}-hello-world-host.install
+ ${S}/debian/${BPN}-hello-world-host.install
# hotp.install
echo "hotp/ta/484d4143-2d53-4841-3120-4a6f636b6542.ta /usr/lib/optee-os/${OPTEE_NAME}/ta" > \
- ${S}/debian/${PN}-hotp-ta.install
+ ${S}/debian/${BPN}-hotp-ta.install
echo "hotp/ta/484d4143-2d53-4841-3120-4a6f636b6542.stripped.elf /usr/lib/optee-os/${OPTEE_NAME}/ta" >> \
- ${S}/debian/${PN}-hotp-ta.install
+ ${S}/debian/${BPN}-hotp-ta.install
echo "hotp/host/optee_example_hotp /usr/lib/optee-os/${OPTEE_NAME}/ca" > \
- ${S}/debian/${PN}-hotp-host.install
+ ${S}/debian/${BPN}-hotp-host.install
# random.install
echo "random/ta/b6c53aba-9669-4668-a7f2-205629d00f86.ta /usr/lib/optee-os/${OPTEE_NAME}/ta" > \
- ${S}/debian/${PN}-random-ta.install
+ ${S}/debian/${BPN}-random-ta.install
echo "random/ta/b6c53aba-9669-4668-a7f2-205629d00f86.stripped.elf /usr/lib/optee-os/${OPTEE_NAME}/ta" >> \
- ${S}/debian/${PN}-random-ta.install
+ ${S}/debian/${BPN}-random-ta.install
echo "random/host/optee_example_random /usr/lib/optee-os/${OPTEE_NAME}/ca" > \
- ${S}/debian/${PN}-random-host.install
+ ${S}/debian/${BPN}-random-host.install
# secure-storage.install
echo "secure_storage/ta/f4e750bb-1437-4fbf-8785-8d3580c34994.ta /usr/lib/optee-os/${OPTEE_NAME}/ta" > \
- ${S}/debian/${PN}-secure-storage-ta.install
+ ${S}/debian/${BPN}-secure-storage-ta.install
echo "secure_storage/ta/f4e750bb-1437-4fbf-8785-8d3580c34994.stripped.elf /usr/lib/optee-os/${OPTEE_NAME}/ta" >> \
- ${S}/debian/${PN}-secure-storage-ta.install
+ ${S}/debian/${BPN}-secure-storage-ta.install
echo "secure_storage/host/optee_example_secure_storage /usr/lib/optee-os/${OPTEE_NAME}/ca" > \
- ${S}/debian/${PN}-secure-storage-host.install
+ ${S}/debian/${BPN}-secure-storage-host.install
}
COMPATIBLE_MACHINE = "^(stm32mp15x)$"
diff --git a/meta/classes-recipe/dracut-module.bbclass b/meta/classes-recipe/dracut-module.bbclass
index 6fce979a..d13ace4f 100644
--- a/meta/classes-recipe/dracut-module.bbclass
+++ b/meta/classes-recipe/dracut-module.bbclass
@@ -15,7 +15,7 @@ DRACUT_MODULE_SETUP = "module-setup.sh"
SRC_URI:append = "file://${DRACUT_MODULE_SETUP}.tmpl"
DRACUT_MODULE_NO ??= "50"
-DRACUT_MODULE_NAME ?= "${@ d.getVar('PN')[7:] if d.getVar('PN').startswith('dracut-') else d.getVar('PN')}"
+DRACUT_MODULE_NAME ?= "${@ d.getVar('BPN')[7:] if d.getVar('BPN').startswith('dracut-') else d.getVar('BPN')}"
DEBIAN_DEPENDS = "dracut-core"
DRACUT_MODULE_PATH = "${D}/usr/lib/dracut/modules.d/${DRACUT_MODULE_NO}${DRACUT_MODULE_NAME}/"
diff --git a/meta/classes-recipe/linux-module.bbclass b/meta/classes-recipe/linux-module.bbclass
index f0b5790c..05a36129 100644
--- a/meta/classes-recipe/linux-module.bbclass
+++ b/meta/classes-recipe/linux-module.bbclass
@@ -5,7 +5,7 @@
#
# SPDX-License-Identifier: MIT
-DESCRIPTION ?= "Custom kernel module ${PN}"
+DESCRIPTION ?= "Custom kernel module ${BPN}"
MAINTAINER ?= "isar-users <isar-users@googlegroups.com>"
KERNEL_NAME ?= ""
@@ -66,7 +66,7 @@ TEMPLATE_VARS += " \
SIGNATURE_CERTFILE \
SIGNATURE_HASHFN \
SIGNATURE_SIGNWITH \
- PN \
+ BPN \
DEBIAN_COMPAT \
DEBIAN_STANDARDS_VERSION"
diff --git a/meta/recipes-bsp/optee-ftpm/files/debian/control.tmpl b/meta/recipes-bsp/optee-ftpm/files/debian/control.tmpl
index 7f41b5c4..22e62c8f 100644
--- a/meta/recipes-bsp/optee-ftpm/files/debian/control.tmpl
+++ b/meta/recipes-bsp/optee-ftpm/files/debian/control.tmpl
@@ -1,4 +1,4 @@
-Source: ${PN}
+Source: ${BPN}
Section: misc
Priority: optional
Standards-Version: ${DEBIAN_STANDARDS_VERSION}
@@ -6,7 +6,7 @@ Maintainer: Unknown maintainer <unknown@example.com>
Build-Depends: debhelper-compat (= ${DEBIAN_COMPAT}), ${DEBIAN_BUILD_DEPENDS}
Rules-Requires-Root: no
-Package: ${PN}
+Package: ${BPN}
Architecture: any
Depends:
Description: TCG reference implementation of the TPM 2.0 Specification.
diff --git a/meta/recipes-kernel/linux-module/files/debian/control.tmpl b/meta/recipes-kernel/linux-module/files/debian/control.tmpl
index d8f4aded..43bf7c14 100644
--- a/meta/recipes-kernel/linux-module/files/debian/control.tmpl
+++ b/meta/recipes-kernel/linux-module/files/debian/control.tmpl
@@ -1,4 +1,4 @@
-Source: ${PN}
+Source: ${BPN}
Section: kernel
Priority: optional
Standards-Version: ${DEBIAN_STANDARDS_VERSION}
@@ -6,7 +6,7 @@ Build-Depends: debhelper-compat (= ${DEBIAN_COMPAT}), ${DEBIAN_BUILD_DEPENDS}
Maintainer: ${MAINTAINER}
Rules-Requires-Root: no
-Package: ${PN}
+Package: ${BPN}
Architecture: any
Depends: ${KERNEL_IMAGE_PKG}, kmod
Description: ${DESCRIPTION}
diff --git a/meta/recipes-kernel/linux-module/files/debian/rules.tmpl b/meta/recipes-kernel/linux-module/files/debian/rules.tmpl
index ff8d551a..66b0e87d 100755
--- a/meta/recipes-kernel/linux-module/files/debian/rules.tmpl
+++ b/meta/recipes-kernel/linux-module/files/debian/rules.tmpl
@@ -62,7 +62,7 @@ ifneq ($(filter pkg.signwith,$(DEB_BUILD_PROFILES)),)
endif
override_dh_auto_install:
- $(MAKE) -C $(KDIR) M=${MODULE_DIR} INSTALL_MOD_PATH=$(PWD)/debian/${PN} modules_install
+ $(MAKE) -C $(KDIR) M=${MODULE_DIR} INSTALL_MOD_PATH=$(PWD)/debian/${BPN} modules_install
%:
CFLAGS= LDFLAGS= dh $@
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-4-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 04/13] linux-distro: provide fake packages for native variant of packages
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (2 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 03/13] debian templates: name package after BPN instead of PN 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 05/13] dpkg-source: let the native package variant own the source package 'Felix Moessbauer' via isar-users
` (8 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
As a preparation to always create the dpkg source package from the
-native variant of a package, we also need to model this for our fake
packages that are only there to satisfy the bitbake dependencies of a
distro provided kernel.
This also aligns the provided recipes of distro kernels with the ones
provided by custom kernels.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta/recipes-kernel/linux/linux-distro.bb | 12 ++++++------
1 file changed, 6 insertions(+), 6 deletions(-)
diff --git a/meta/recipes-kernel/linux/linux-distro.bb b/meta/recipes-kernel/linux/linux-distro.bb
index 8fc1bcb7..f38e2450 100644
--- a/meta/recipes-kernel/linux/linux-distro.bb
+++ b/meta/recipes-kernel/linux/linux-distro.bb
@@ -16,14 +16,14 @@ python() {
for kernel in distro_kernels.split():
for prefix in ['linux-image', 'linux-headers', 'linux-kbuild']:
- d.appendVar('PROVIDES', ' {}-{}'.format(prefix, kernel))
- d.appendVar('RPROVIDES', ' {}-{}'.format(prefix, kernel))
+ d.appendVar('PROVIDES', ' {0}-{1} {0}-{1}-native'.format(prefix, kernel))
+ d.appendVar('RPROVIDES', ' {0}-{1} {0}-{1}-native'.format(prefix, kernel))
if kernel_img_pkg:
- d.appendVar('PROVIDES', ' ' + kernel_img_pkg)
- d.appendVar('RPROVIDES', ' ' + kernel_img_pkg)
+ d.appendVar('PROVIDES', ' {0} {0}-native'.format(kernel_img_pkg))
+ d.appendVar('RPROVIDES', ' {0} {0}-native'.format(kernel_img_pkg))
if kernel_headers_pkg:
- d.appendVar('PROVIDES', ' ' + kernel_headers_pkg)
- d.appendVar('RPROVIDES', ' ' + kernel_headers_pkg)
+ d.appendVar('PROVIDES', ' {0} {0}-native'.format(kernel_headers_pkg))
+ d.appendVar('RPROVIDES', ' {0} {0}-native'.format(kernel_headers_pkg))
}
inherit multiarch
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-5-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 05/13] dpkg-source: let the native package variant own the source package
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (3 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 04/13] linux-distro: provide fake packages for native variant of packages 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 06/13] do not assert on legitimate re-execution of tasks 'Felix Moessbauer' via isar-users
` (7 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
We currently build the source package just for PN==BPN and otherwise
fetch the package. This logic was implemented in 2ca3a7e to fix race
conditions on the package, as well as issues due to them not having bit
identical content. In 826acb3 logic was added to deploy the source
package via the sstate cache, which also made the generated package
accessible from both PN and BPN / variant builds.
We now model the dependencies explicitly, whereby the -native
variant of the package (on cross) owns the source package and all
consumers depend on that. By that, we can also drop the fetch code.
This has the additional advantage of sharing the source packages cross
architecture in the sstate cache.
As the kernel source package is architecture specific, we exclude it
from the -native redirect.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
RECIPE-API-CHANGELOG.md | 14 ++++
meta/classes-recipe/container-loader.bbclass | 1 +
meta/classes-recipe/dpkg-source.bbclass | 79 +++-----------------
meta/classes-recipe/linux-kernel.bbclass | 3 +
meta/classes-recipe/linux-module.bbclass | 3 +
5 files changed, 32 insertions(+), 68 deletions(-)
diff --git a/RECIPE-API-CHANGELOG.md b/RECIPE-API-CHANGELOG.md
index 3798a9d1..4711fb72 100644
--- a/RECIPE-API-CHANGELOG.md
+++ b/RECIPE-API-CHANGELOG.md
@@ -1225,3 +1225,17 @@ the rootfs. This has been replaced by the `exclude-docs` rootfs feature. The
When enabled, the package changelogs are now removed as well (copyright is still
kept for legal reasons).
+
+### Debian source package is generated from the -native variant
+
+Previously, the base recipe (`${BPN}`) built the source package while all other
+variants merely fetched the resulting artifact. When building for multiple
+architectures, every one of them produced its own source package, even though
+only a single one is ever deployed to `DEPLOY_DIR_SRC`.
+
+Since the source package is architecture independent, it is now always built by
+the `-native` variant. Only the `do_dpkg_source` task of that variant has to be
+runnable, the variant itself does not need to build to completion. In addition,
+the name and the content of the source package must be derived from `${BPN}`
+alone, never from `${PN}`. If a source package depends on the architecture,
+set `SRCPKG_PROVIDER = "${BPN}"` after `inherit dpkg` (or alike).
diff --git a/meta/classes-recipe/container-loader.bbclass b/meta/classes-recipe/container-loader.bbclass
index 8439db53..31c6e245 100644
--- a/meta/classes-recipe/container-loader.bbclass
+++ b/meta/classes-recipe/container-loader.bbclass
@@ -17,6 +17,7 @@ DEBIAN_PROVIDES := "${BPN}"
PN .= "-${DISTRO_ARCH}"
DPKG_ARCH ?= "${DISTRO_ARCH}"
DEBIAN_MULTI_ARCH ?= "allowed"
+SRCPKG_PROVIDER = "${BPN}"
CONTAINER_DELETE_AFTER_LOAD ?= "0"
diff --git a/meta/classes-recipe/dpkg-source.bbclass b/meta/classes-recipe/dpkg-source.bbclass
index 6f9091a8..16d423d3 100644
--- a/meta/classes-recipe/dpkg-source.bbclass
+++ b/meta/classes-recipe/dpkg-source.bbclass
@@ -82,75 +82,18 @@ do_deploy_source() {
}
addtask deploy_source after do_dpkg_source
-do_dpkg_build[depends] += "${BPN}:do_deploy_source"
+# The source package is architecture independent, so it is owned by the -native
+# variant when cross building. Without one, the base recipe also provides
+# ${BPN}-native (see multiarch.bbclass), so this resolves in both cases.
+SRCPKG_PROVIDER = "${@'${BPN}-native' if d.getVar('HOST_ARCH') != d.getVar('DISTRO_ARCH') else '${BPN}'}"
+
+do_dpkg_build[depends] += "${SRCPKG_PROVIDER}:do_deploy_source"
# ensure that the source package is deployed into isar-apt
-do_deploy_deb[rdepends] += "${BPN}:do_deploy_source"
+do_deploy_deb[rdepends] += "${SRCPKG_PROVIDER}:do_deploy_source"
SCHROOT_MOUNTS = "${WORKDIR}:/work ${REPO_ISAR_DIR}/${DISTRO}:/isar-apt"
-fetch_common_source_schroot() {
- schroot_create_configs
- insert_mounts
-
- session_id=$(schroot -q -b -c ${SBUILD_CHROOT})
- echo "Started session: ${session_id}"
-
- schroot_cleanup() {
- schroot -q -f -e -c ${session_id} > /dev/null 2>&1
- remove_mounts > /dev/null 2>&1
- schroot_delete_configs
- }
- trap 'exit 1' INT HUP QUIT TERM ALRM USR1
- trap 'schroot_cleanup' EXIT
-
- E="${@ isar_export_proxies(d)}"
-
- schroot -r -c ${session_id} -d / -u root -- \
- apt-get update -o Dir::Etc::SourceList="sources.list.d/isar-apt.list" -o Dir::Etc::SourceParts="-" -o APT::Get::List-Cleanup="0"
- schroot -r -c ${session_id} -d / -- \
- sh -c '
- cd /work
- apt-get -y --download-only --only-source -o Debug::NoLocking=1 -o Acquire::Source-Symlinks="false" source ${DEBIAN_SOURCE}'
-
- schroot -e -c ${session_id}
- remove_mounts
- schroot_delete_configs
-}
-
-UNSHARE_DPKG_SOURCE_CHROOT = "${WORKDIR}/dpkg-source-chroot"
-fetch_common_source_unshare() {
- run_privileged_heredoc <<'EOF'
- set -e
- mkdir -p ${UNSHARE_DPKG_SOURCE_CHROOT}
- tar -xf "${SBUILD_CHROOT}" -C ${UNSHARE_DPKG_SOURCE_CHROOT}
-
- ${@insert_isar_mounts(d, d.getVar('UNSHARE_DPKG_SOURCE_CHROOT'), d.getVar('SCHROOT_MOUNTS'))}
- chroot ${UNSHARE_DPKG_SOURCE_CHROOT} /bin/bash -s <<'EOAPT'
- set -e
- apt-get update \
- -o Dir::Etc::SourceList="sources.list.d/isar-apt.list" \
- -o Dir::Etc::SourceParts="-" \
- -o APT::Get::List-Cleanup="0"
-
- cd /work
- apt-get -y --download-only --only-source \
- -o Debug::NoLocking=1 -o Acquire::Source-Symlinks="false" \
- source ${DEBIAN_SOURCE}
-EOAPT
-EOF
-
- # run cleanup in separate session to ensure nothing is mounted
- run_privileged rm -rf ${UNSHARE_DPKG_SOURCE_CHROOT}
-}
-
-do_fetch_common_source[depends] += "${SCHROOT_DEP} ${BPN}:do_deploy_source"
-do_fetch_common_source[lockfiles] = "${REPO_ISAR_DIR}/isar.lock"
-do_fetch_common_source[network] = "${TASK_USE_SUDO}"
-do_fetch_common_source[depends] += "base-apt:do_cache isar-apt:do_cache_config"
-do_fetch_common_source() {
- fetch_common_source_${ISAR_CHROOT_MODE}
-}
-addtask fetch_common_source
-
-do_dpkg_build[depends] += "${@'${PN}:do_dpkg_source' if '${PN}' == '${BPN}' else '${PN}:do_fetch_common_source'}"
-do_clean[depends] += "${@'' if '${PN}' == '${BPN}' else '${BPN}:do_clean'}"
+# All variants share BPN and thus DEPLOY_DIR_SRC, so only the provider builds a
+# source package, everybody else consumes the one deployed there.
+do_dpkg_build[depends] += "${SRCPKG_PROVIDER}:do_dpkg_source"
+do_clean[depends] += "${@'' if '${PN}' == '${SRCPKG_PROVIDER}' else '${SRCPKG_PROVIDER}:do_clean'}"
diff --git a/meta/classes-recipe/linux-kernel.bbclass b/meta/classes-recipe/linux-kernel.bbclass
index ac587b17..60bf2a49 100644
--- a/meta/classes-recipe/linux-kernel.bbclass
+++ b/meta/classes-recipe/linux-kernel.bbclass
@@ -102,6 +102,9 @@ inherit dpkg
inherit kbuildtarget
inherit libctarget
+# The kernel source package is architecture specific
+SRCPKG_PROVIDER = "${BPN}"
+
# Add custom cflags to the kernel build
KCFLAGS ?= "-fdebug-prefix-map=${CURDIR}=."
KAFLAGS ?= "-fdebug-prefix-map=${CURDIR}=."
diff --git a/meta/classes-recipe/linux-module.bbclass b/meta/classes-recipe/linux-module.bbclass
index 05a36129..76bf03f7 100644
--- a/meta/classes-recipe/linux-module.bbclass
+++ b/meta/classes-recipe/linux-module.bbclass
@@ -51,6 +51,9 @@ python() {
inherit dpkg
inherit per-kernel
+# The kernel module source package is architecture specific
+SRCPKG_PROVIDER = "${BPN}"
+
TEMPLATE_FILES = "debian/control.tmpl \
debian/rules.tmpl"
TEMPLATE_VARS += " \
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-6-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 06/13] do not assert on legitimate re-execution of tasks
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (4 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 05/13] dpkg-source: let the native package variant own the source package 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 07/13] bitbake: backport cooker: use BB_HASHSERVE_DB_DIR for hash server database location 'Felix Moessbauer' via isar-users
` (6 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
When running with sstate cache and a bitbake hashequiv server, tasks can
be re-executed even though this does not indicate false sharing of a
WORKDIR. The false-sharing detector in isar-events must not assert on
these cases.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta/classes-global/isar-events.bbclass | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/meta/classes-global/isar-events.bbclass b/meta/classes-global/isar-events.bbclass
index 15bfdb99..692bcaf7 100644
--- a/meta/classes-global/isar-events.bbclass
+++ b/meta/classes-global/isar-events.bbclass
@@ -23,6 +23,9 @@ def task_once_stamp(d):
addhandler task_started
python task_started() {
+ # when using a hashequiv server, the same task may be executed multiple times
+ if d.getVar('BB_SIGNATURE_HANDLER') == 'OEEquivHash':
+ return
try:
f = open(task_once_stamp(d), "x")
f.close()
@@ -37,6 +40,8 @@ task_started[eventmask] = "bb.build.TaskStarted"
addhandler task_failed
python task_failed() {
+ if d.getVar('BB_SIGNATURE_HANDLER') == 'OEEquivHash':
+ return
# Avoid false positives if a second target depends on this task and retries
# the execution after the first failure.
os.remove(task_once_stamp(d))
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-7-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 07/13] bitbake: backport cooker: use BB_HASHSERVE_DB_DIR for hash server database location
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (5 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 06/13] do not assert on legitimate re-execution of tasks 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 08/13] set default sstate signature handler to OEEquivHash 'Felix Moessbauer' via isar-users
` (5 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff,
Felix Moessbauer, Alexander Kanavin
Backport of upstream commit b339d05ad2b69a6518522ee4c46dd5f5a6e33f65.
If unset, the existing behavior is preseved.
The use case is sharing the database in bitbake-setup's driven builds
without having to set up/start/stop a common single server shared
between them (this is added to bitbake-setup in the next commit).
Also create the specified directory if it doesn't yet exist.
Add a check that the directory is not on a NFS path, and error out then,
guiding the user to set up a standalone hash equivalency server.
Note: the check runs 'stat' executable with a format string parameter,
ensuring it prints only the filesystem type and nothing else.
Python's standard library does not have a statfs() wrapper,
and using ctypes to call into it would've required delicate,
crash-prone data type definitions, full of magic numbers.
Signed-off-by: Alexander Kanavin <alex@linutronix.de>
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
.../bitbake-user-manual-ref-variables.rst | 23 +++++++++++++++++++
bitbake/lib/bb/cooker.py | 11 ++++++++-
bitbake/lib/bb/utils.py | 9 ++++++++
3 files changed, 42 insertions(+), 1 deletion(-)
diff --git a/bitbake/doc/bitbake-user-manual/bitbake-user-manual-ref-variables.rst b/bitbake/doc/bitbake-user-manual/bitbake-user-manual-ref-variables.rst
index 899e584f..c41df199 100644
--- a/bitbake/doc/bitbake-user-manual/bitbake-user-manual-ref-variables.rst
+++ b/bitbake/doc/bitbake-user-manual/bitbake-user-manual-ref-variables.rst
@@ -414,6 +414,29 @@ overview of their function and contents.
equivalences that correspond to Share State caches that are
only available on specific clients.
+ :term:`BB_HASHSERVE_DB_DIR`
+ When :term:`BB_HASHSERVE` is set to ``auto``, bitbake will use
+ a private location inside a particular build directory for the sqlite
+ database file that holds hash equivalency data.
+
+ This variable allows using a different path, which can be shared
+ between multiple build directories and bitbake instances
+ that operate on them. This enables using a common ``${SSTATE_DIR}``
+ together with common hash equivalency data for local builds, without having to
+ separately manage a hash equivalency server.
+
+ .. note::
+
+ This variable cannot be set to a NFS mount and bitbake will error out then.
+ The reason is that NFS implementations can have file locking issues, which
+ can cause data loss and corruption when there are multiple writers operating
+ on a file at the same time as explained in https://sqlite.org/faq.html#q5
+
+ If you'd like to share hash equivalency data between multiple computers, you
+ need to set up a hash equivalency server separately and point :term:`BB_HASHSERVE`
+ to it. See https://docs.yoctoproject.org/dev-manual/hashequivserver.html for
+ additional information.
+
:term:`BB_HASHSERVE_UPSTREAM`
Specifies an upstream Hash Equivalence server.
diff --git a/bitbake/lib/bb/cooker.py b/bitbake/lib/bb/cooker.py
index 701cf51b..8ac5e07a 100644
--- a/bitbake/lib/bb/cooker.py
+++ b/bitbake/lib/bb/cooker.py
@@ -312,7 +312,16 @@ class BBCooker:
if self.data.getVar("BB_HASHSERVE") == "auto":
# Create a new hash server bound to a unix domain socket
if not self.hashserv:
- dbfile = (self.data.getVar("PERSISTENT_DIR") or self.data.getVar("CACHE")) + "/hashserv.db"
+ bb_hashserve_db_dir = self.data.getVar("BB_HASHSERVE_DB_DIR")
+ if bb_hashserve_db_dir and utils.is_path_on_nfs(bb_hashserve_db_dir):
+ bb.fatal("""Hash equivalency database location (set via BB_HASHSERVE_DB_DIR to {})
+cannot be on a NFS mount due to potential NFS locking issues between sqlite clients, per https://sqlite.org/faq.html#q5
+
+If you need to share the database between several computers, set up a permanently running hash equivalency server
+according to https://docs.yoctoproject.org/dev-manual/hashequivserver.html""".format(bb_hashserve_db_dir))
+ dbdir = bb_hashserve_db_dir or self.data.getVar("PERSISTENT_DIR") or self.data.getVar("CACHE")
+ os.makedirs(dbdir, exist_ok=True)
+ dbfile = dbdir + "/hashserv.db"
upstream = self.data.getVar("BB_HASHSERVE_UPSTREAM") or None
if upstream:
import socket
diff --git a/bitbake/lib/bb/utils.py b/bitbake/lib/bb/utils.py
index ebee65d3..3866c1b8 100644
--- a/bitbake/lib/bb/utils.py
+++ b/bitbake/lib/bb/utils.py
@@ -1866,3 +1866,12 @@ def lock_timeout(lock):
yield held
finally:
lock.release()
+
+
+def is_path_on_nfs(path):
+ """
+ Returns True if ``path`` argument is on a NFS mount.
+ """
+ import bb.process
+ fstype = bb.process.run("stat -f -c %T {}".format(path))[0].strip()
+ return fstype == "nfs"
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-8-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 08/13] set default sstate signature handler to OEEquivHash
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (6 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 07/13] bitbake: backport cooker: use BB_HASHSERVE_DB_DIR for hash server database location 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 09/13] testsuite: add support to run with bitbake hashserver 'Felix Moessbauer' via isar-users
` (4 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
Using the OE hash equivalence drastically reduces build times on
repeated builds, given that all sstate artifacts are reproducible.
This feature has been extensively tested in Yocto and also is the new
default there. By that, we switch as well.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
RECIPE-API-CHANGELOG.md | 11 +++++++++++
meta/conf/bitbake.conf | 3 ++-
2 files changed, 13 insertions(+), 1 deletion(-)
diff --git a/RECIPE-API-CHANGELOG.md b/RECIPE-API-CHANGELOG.md
index 4711fb72..f606ecaa 100644
--- a/RECIPE-API-CHANGELOG.md
+++ b/RECIPE-API-CHANGELOG.md
@@ -1239,3 +1239,14 @@ runnable, the variant itself does not need to build to completion. In addition,
the name and the content of the source package must be derived from `${BPN}`
alone, never from `${PN}`. If a source package depends on the architecture,
set `SRCPKG_PROVIDER = "${BPN}"` after `inherit dpkg` (or alike).
+
+### Default sstate signature handler changed to OEEquivHash
+
+The default `BB_SIGNATURE_HANDLER` is now `OEEquivHash` (instead of `OEBasicHash`),
+and `BB_HASHSERVE` defaults to `auto`. Using BitBake's hash equivalence drastically
+reduces build times on repeated builds by reusing sstate artifacts across signature
+changes, provided that the artifacts are reproducible.
+
+To preserve the hash equivalence database across `TMPDIR` cleanups, set the
+`BB_HASHSERVE_DB_DIR` environment variable to a persistent location, ideally
+managed together with the `SSTATE_DIR`.
diff --git a/meta/conf/bitbake.conf b/meta/conf/bitbake.conf
index c31719b8..cbe284df 100644
--- a/meta/conf/bitbake.conf
+++ b/meta/conf/bitbake.conf
@@ -98,7 +98,8 @@ REPO_BASE_DIR = "${DEPLOY_DIR}/base-apt/${DISTRO}/apt"
REPO_BASE_DB_DIR = "${DEPLOY_DIR}/base-apt/${DISTRO}/db"
# Setup our default hash policy
-BB_SIGNATURE_HANDLER ?= "OEBasicHash"
+BB_SIGNATURE_HANDLER ?= "OEEquivHash"
+BB_HASHSERVE ??= "auto"
BB_HASHEXCLUDE_ISAR ?= "CCACHE_DEBUG LAYERDIR_core SCRIPTSDIR TOPDIR ISAR_BUILD_UUID \
RUN_PRIVILEGED_CMD UNSHARE_SUBUID_BASE GNUPGHOME"
BB_HASHEXCLUDE_COMMON ?= "TMPDIR FILE PATH PWD BB_TASKHASH BBPATH BBSERVER DL_DIR \
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-9-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 09/13] testsuite: add support to run with bitbake hashserver
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (7 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 08/13] set default sstate signature handler to OEEquivHash 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 10/13] isar-sstate: add support to clean hashes from hashequiv server 'Felix Moessbauer' via isar-users
` (3 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
The bitbake hashserver stores sstate artifact hashes (task outputs), to
check which task inputs create the same task output. This helps to get a
better sstate cache hitrate, resulting in shorter build times (on
repeated builds with sstate cache).
To ensure that the hashserver received the SIGINT / SIGTERM on container
termination (needed for db closing), we exec avocado, which makes it a
direct child of the containers init process.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
testsuite/cibuilder.py | 2 ++
testsuite/dockerdata/test-container-entrypoint | 2 +-
2 files changed, 3 insertions(+), 1 deletion(-)
diff --git a/testsuite/cibuilder.py b/testsuite/cibuilder.py
index 0565f158..414a2b3e 100755
--- a/testsuite/cibuilder.py
+++ b/testsuite/cibuilder.py
@@ -257,6 +257,8 @@ class CIBuilder(Test):
f.write('SSTATE_DIR = "%s"\n' % sstate_dir)
if sstate and 'SSTATE_MIRRORS' in os.environ:
f.write('SSTATE_MIRRORS = "%s"\n' % os.environ['SSTATE_MIRRORS'])
+ if 'BB_HASHSERVE_DB_DIR' in os.environ:
+ f.write('BB_HASHSERVE_DB_DIR = "%s"\n' % os.environ['BB_HASHSERVE_DB_DIR'])
if image_install is not None:
f.write('IMAGE_INSTALL = "%s"\n' % image_install)
else:
diff --git a/testsuite/dockerdata/test-container-entrypoint b/testsuite/dockerdata/test-container-entrypoint
index aa3def79..d263760d 100755
--- a/testsuite/dockerdata/test-container-entrypoint
+++ b/testsuite/dockerdata/test-container-entrypoint
@@ -124,6 +124,6 @@ if [ "${start_shell}" = 1 ]; then
bash
else
set -x
- avocado ${showopt} run ${args}
+ exec avocado ${showopt} run ${args}
fi
'
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-10-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 10/13] isar-sstate: add support to clean hashes from hashequiv server
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (8 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 09/13] testsuite: add support to run with bitbake hashserver 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 11/13] rootfs: use host apt to install packages into rootfs 'Felix Moessbauer' via isar-users
` (2 subsequent siblings)
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
The sstate cache and the hash equivalence data should be kept in sync
(in case hash-equivalence is used). For that, we a add a runtime option
to also clean the hashes from a running (external) hash equivalence
server.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
scripts/isar-sstate | 39 ++++++++++++++++++++++++++++++++++++++-
1 file changed, 38 insertions(+), 1 deletion(-)
diff --git a/scripts/isar-sstate b/scripts/isar-sstate
index 36a91134..d94091c8 100755
--- a/scripts/isar-sstate
+++ b/scripts/isar-sstate
@@ -49,6 +49,13 @@ files can be kept longer, as indicated by `--max-sig-age`. If not set explicitly
this defaults to `max_age`, and any explicitly given value can't be smaller
than `max_age`.
+If `--hashequiv-server` is given, the unihashes of the deleted archive files are
+also dropped from that hash equivalence server using `bitbake-hashclient remove`.
+Note, that the command has to be called from a bitbake environment. For a local
+sstate cache, start a local hash server and then run the clean command as follows:
+ bitbake-hashserv -d $BB_HASHSERVE_DB_DIR/hashserv.db &
+ isar-sstate clean <...> --hashequiv-server unix://.hashserve.sock $SSTATE_DIR
+
### info
The `info` command scans the remote cache and displays some basic statistics.
@@ -145,6 +152,7 @@ from fnmatch import fnmatchcase
import os
import re
import shutil
+import subprocess
import sys
from tempfile import NamedTemporaryFile
import time
@@ -677,6 +685,10 @@ def arguments():
parser.add_argument(
'--excluded-tasks', type=str, default=DEFAULT_IGNORED_TASKS,
help="lint: comma-separated list of tasks to ignore (default: %(default)s)")
+ parser.add_argument(
+ '--hashequiv-server', type=str, default=None,
+ help="clean: also remove the unihashes of deleted artifacts from this hashequiv server"
+ )
args = parser.parse_args()
if args.command in 'upload analyze'.split() and args.source is None:
@@ -734,7 +746,24 @@ def sstate_upload(source, target, verbose, filter, arch, **kwargs):
return 0
-def sstate_clean(target, max_age, max_sig_age, verbose, filter, arch, **kwargs):
+def hashequiv_remove(server, unihashes, verbose):
+ """Drop the given unihashes from the hash equivalence server."""
+ hashclient = shutil.which('bitbake-hashclient')
+ if hashclient is None:
+ raise RuntimeError("bitbake-hashclient not found, cannot clean hashequiv server")
+
+ print(f"INFO: removing {len(unihashes)} unihashes from {server}")
+ for unihash in unihashes:
+ if verbose:
+ print(f"[UNIHASH] {unihash}")
+ cmd = [hashclient, '--address', server, 'remove', '--where', 'unihash', unihash]
+ try:
+ subprocess.run(cmd, capture_output=True, text=True, check=True)
+ except subprocess.CalledProcessError as e:
+ raise RuntimeError(f"could not remove unihash {unihash}: {e.stderr.strip()}") from e
+
+
+def sstate_clean(target, max_age, max_sig_age, verbose, filter, arch, hashequiv_server=None, **kwargs):
def convert_to_seconds(x):
seconds_per_unit = {'s': 1, 'm': 60, 'h': 3600, 'd': 86400, 'w': 604800}
m = re.match(r'^(\d+)(w|d|h|m|s)?', x)
@@ -776,6 +805,14 @@ def sstate_clean(target, max_age, max_sig_age, verbose, filter, arch, **kwargs):
print(f"INFO: found {len(siginfo_files)} siginfo files, {len(del_siginfo_files)} of which "
f"correspond to old archive files or are older than {max_sig_age}")
+ if hashequiv_server:
+ # drop the hashes first, the server must never point to artifacts we deleted
+ try:
+ hashequiv_remove(hashequiv_server, sorted(set(del_archive_hashes)), verbose)
+ except RuntimeError as e:
+ print(f"ERROR: {e}")
+ return 1
+
for f in del_archive_files + del_siginfo_files:
if verbose:
print(f"[DELETE] {f.path}")
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-11-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 11/13] rootfs: use host apt to install packages into rootfs
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (9 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 10/13] isar-sstate: add support to clean hashes from hashequiv server 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 12/13] bootstrap: do not include apt 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 13/13] bootstrap: do not add ca-certificates 'Felix Moessbauer' via isar-users
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
We currently use the apt inside the rootfs to operate on the rootfs.
This has two major disadvantages:
1. on non-native, the apt invocations are emulated (including the
extraction of the packages and downloading)
2. apt must be installed in the rootfs (which makes the rootfs larger
and pulls in a lot of static-build-using dependencies related to the
rust parts, which is relevant for license clearing)
We change that similar to how mmdebstrap is doing it: Use the host apt
to operate on the chroot, whereby dpkg itself runs inside the chroot to
have proper support for the maintainer scripts. By that, apt is not
emulated and the generated chroots can be much smaller.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta/classes-recipe/deb-dl-dir.bbclass | 34 ++++++
meta/classes-recipe/rootfs.bbclass | 145 ++++++++++---------------
2 files changed, 89 insertions(+), 90 deletions(-)
diff --git a/meta/classes-recipe/deb-dl-dir.bbclass b/meta/classes-recipe/deb-dl-dir.bbclass
index bafe3a63..3f41f9e1 100644
--- a/meta/classes-recipe/deb-dl-dir.bbclass
+++ b/meta/classes-recipe/deb-dl-dir.bbclass
@@ -178,3 +178,37 @@ deb_dl_dir_export() {
done
EOF
}
+
+# Point isar-apt at its real build-path location so host apt can access it.
+# The reproducible 'file:///isar-apt' encodes to the apt list prefix '_isar-apt',
+# the real repo path encodes to the same path with '/' replaced by '_'.
+deb_dl_dir_isar_apt_to_host() {
+ export rootfs=$1
+ export host_prefix="$(printf '%s' '${REPO_ISAR_DIR}/${DISTRO}' | tr '/' '_')"
+ run_privileged_heredoc << ' EOSUDO'
+ set -e
+ sed -i 's|file:///isar-apt|file://${REPO_ISAR_DIR}/${DISTRO}|g' \
+ "${rootfs}/etc/apt/sources.list.d/isar-apt.list"
+ for f in "${rootfs}/var/lib/apt/lists/"_isar-apt*; do
+ [ -e "$f" ] || continue
+ suffix="$(basename "$f" | sed 's|^_isar-apt||')"
+ mv "$f" "${rootfs}/var/lib/apt/lists/${host_prefix}${suffix}"
+ done
+ EOSUDO
+}
+
+# Revert the deb_dl_dir_isar_apt_to_host changes.
+deb_dl_dir_isar_apt_to_target() {
+ export rootfs=$1
+ export host_prefix="$(printf '%s' '${REPO_ISAR_DIR}/${DISTRO}' | tr '/' '_')"
+ run_privileged_heredoc << ' EOSUDO'
+ set -e
+ sed -i 's|file://${REPO_ISAR_DIR}/${DISTRO}|file:///isar-apt|g' \
+ "${rootfs}/etc/apt/sources.list.d/isar-apt.list"
+ for f in "${rootfs}/var/lib/apt/lists/${host_prefix}"*; do
+ [ -e "$f" ] || continue
+ suffix="$(basename "$f" | sed "s|^${host_prefix}||")"
+ mv "$f" "${rootfs}/var/lib/apt/lists/_isar-apt${suffix}"
+ done
+ EOSUDO
+}
diff --git a/meta/classes-recipe/rootfs.bbclass b/meta/classes-recipe/rootfs.bbclass
index 4fd627c2..994e8662 100644
--- a/meta/classes-recipe/rootfs.bbclass
+++ b/meta/classes-recipe/rootfs.bbclass
@@ -65,6 +65,16 @@ ROOTFS_FEATURES:remove:focal = "generate-sbom"
# Capture all information needed for sbom generation
ROOTFS_APT_STATE = "apt-state.tar.zst"
ROOTFS_APT_ARGS="install --yes -o Debug::pkgProblemResolver=yes"
+ROOTFS_HOST_APT_OPTS = "-o Dir=${ROOTFSDIR} -o APT::Architecture=${ROOTFS_ARCH} -o DPkg::Chroot-Directory=${ROOTFSDIR}"
+
+# The host apt-get used to populate the rootfs must honor the rootfs' own apt
+# configuration fragments instead of the host's /etc/apt. A command-line '-o' is
+# applied too late (after apt has already read its config parts), so point apt at
+# the chroot via APT_CONFIG, which is parsed during apt initialization - before
+# the config parts directory is read. No host file is touched.
+ROOTFS_HOST_APT_CONFIG = "${WORKDIR}/isar-host-apt.conf"
+# Wrapper to run the host apt-get with that configuration.
+HOST_APT_CMD = "env APT_CONFIG=${ROOTFS_HOST_APT_CONFIG} /usr/bin/apt-get ${ROOTFS_HOST_APT_OPTS}"
ROOTFS_CLEAN_FILES="/etc/hostname /etc/resolv.conf"
@@ -76,7 +86,7 @@ ROOTFS_INITRD_STUBS = "update-initramfs"
ROOTFS_INITRD_STUBS += "${@ ' dracut' if bb.utils.to_boolean(d.getVar('ROOTFS_USE_DRACUT')) else '' }"
# list of <outer>:<inner> or <outer> mount entries
-ROOTFS_MOUNTS ??= "${REPO_ISAR_DIR}/${DISTRO}:/isar-apt ${WORKDIR}:/isar-work"
+ROOTFS_MOUNTS ??= "${WORKDIR}:/isar-work"
python () {
mounts = d.getVar('ROOTFS_MOUNTS', False)
@@ -102,75 +112,6 @@ export LANG ??= "C"
export LANGUAGE ??= "C"
export LC_ALL ??= "C"
-# Execute a command against a rootfs and with isar-apt bind-mounted.
-# Additional mounts may be specified using --bind <source> <target> and a
-# custom directory for the command to be executed with --chdir <dir>. The
-# command is assumed to follow the special "--" argument. This would replace
-# "sudo chroot" calls especially when a native command may be used instead of
-# chroot'ed command and without elevated privileges (the command will likely
-# take the rootfs as argument; e.g. apt-get -o Dir=${ROOTFSDIR}). If the
-# optional rootfs argument is omitted, the host rootfs will be used (e.g. to
-# run native commands): this should be used with care.
-#
-# Usage: rootfs_cmd [options] [rootfs] -- command
-#
-rootfs_cmd() {
- set -- "$@"
- bwrap_args="--bind ${REPO_ISAR_DIR}/${DISTRO} /isar-apt"
- bwrap_binds=""
- bwrap_rootfs=""
-
- while [ "${#}" -gt "0" ] && [ "$1" != "--" ]; do
- case "$1" in
- --bind)
- if [ "${#}" -lt "3" ]; then
- bbfatal "--bind requires two arguments"
- fi
- bwrap_binds="${bwrap_binds} --bind $2 $3"
- shift 3
- ;;
- --chdir)
- if [ "${#}" -lt "2" ]; then
- bbfatal "$1 requires an argument"
- fi
- bwrap_args="${bwrap_args} $1 $2"
- shift 2
- ;;
- -*)
- bbfatal "$1 is not a supported option!"
- ;;
- *)
- if [ -z "${bwrap_rootfs}" ]; then
- bwrap_rootfs="$1"
- shift
- else
- bbfatal "unexpected argument '$1'"
- fi
- ;;
- esac
- done
-
- if [ -n "${bwrap_rootfs}" ]; then
- bwrap_args="${bwrap_args} --bind ${bwrap_rootfs} /"
- fi
-
- if [ "${#}" -le "1" ] || [ "$1" != "--" ]; then
- bbfatal "no command specified (missing --)"
- fi
- shift # remove "--", command and its arguments follows
-
- # bin, lib and lib64 are only real directories on unmerged-usr rootfs
- for ro_d in bin etc lib lib64 sys usr var; do
- [ -d ${bwrap_rootfs}/${ro_d} ] && [ ! -L ${bwrap_rootfs}/${ro_d} ] || continue
- bwrap_args="${bwrap_args} --ro-bind ${bwrap_rootfs}/${ro_d} /${ro_d}"
- done
-
- bwrap --unshare-user --unshare-pid ${bwrap_args} \
- --dev-bind /dev /dev --proc /proc --tmpfs /tmp \
- ${@'--bind "${REPO_ISAR_DIR}/${DISTRO}" /isar-apt' if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''} \
- ${bwrap_binds} -- "${@}"
-}
-
rootfs_do_mounts[weight] = "3"
python rootfs_do_mounts() {
if d.getVar('ISAR_CHROOT_MODE') == 'schroot':
@@ -293,6 +234,20 @@ EOF
EOSUDO
}
+ROOTFS_CONFIGURE_COMMAND += "rootfs_redirect_isar_apt_to_host"
+rootfs_redirect_isar_apt_to_host() {
+ if [ -f "${ROOTFSDIR}/etc/apt/sources.list.d/isar-apt.list" ]; then
+ deb_dl_dir_isar_apt_to_host "${ROOTFSDIR}"
+ fi
+}
+
+# restore by latest before capturing the apt state and before sstate caching
+rootfs_redirect_isar_apt_to_target() {
+ if [ -f "${ROOTFSDIR}/etc/apt/sources.list.d/isar-apt.list" ]; then
+ deb_dl_dir_isar_apt_to_target "${ROOTFSDIR}"
+ fi
+}
+
ROOTFS_CONFIGURE_COMMAND += "rootfs_configure_apt"
rootfs_configure_apt[weight] = "2"
rootfs_configure_apt() {
@@ -315,6 +270,14 @@ rootfs_configure_apt() {
EOSUDO
}
+# Point the host apt-get at the rootfs' apt.conf.d (see ROOTFS_HOST_APT_CONFIG).
+ROOTFS_CONFIGURE_COMMAND =+ "rootfs_configure_host_apt_config"
+rootfs_configure_host_apt_config[weight] = "1"
+rootfs_configure_host_apt_config() {
+ echo 'Dir::Etc::parts "${ROOTFSDIR}/etc/apt/apt.conf.d";' \
+ > '${ROOTFS_HOST_APT_CONFIG}'
+}
+
rootfs_exclude_docs_drop() {
if [ -d '${ROOTFSDIR}/usr/share/man' ]; then
find '${ROOTFSDIR}/usr/share/man/' -mindepth 1 ! -type d -delete
@@ -371,7 +334,7 @@ rootfs_install_pkgs_update() {
run_privileged_heredoc <<'EOF'
set -e
${@insert_isar_mounts(d, d.getVar('ROOTFSDIR'), d.getVar('ROOTFS_MOUNTS')) if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''}
- chroot '${ROOTFSDIR}' /usr/bin/apt-get update \
+ ${HOST_APT_CMD} update \
-o Dir::Etc::SourceList="sources.list.d/isar-apt.list" \
-o Dir::Etc::SourceParts="-" \
-o APT::Get::List-Cleanup="0"
@@ -402,10 +365,14 @@ rootfs_install_pkgs_download[progress] = "custom:rootfs_progress.PkgsDownloadPro
rootfs_install_pkgs_download[isar-apt-lock] = "release-after"
rootfs_install_pkgs_download[network] = "${TASK_USE_NETWORK}"
rootfs_install_pkgs_download() {
- # download packages using apt in a non-privileged namespace
- rootfs_cmd --bind "${ROOTFSDIR}/var/cache/apt/archives" /var/cache/apt/archives \
- ${ROOTFSDIR} \
- -- /usr/bin/apt-get ${ROOTFS_APT_ARGS} -o Debug::NoLocking=1 --download-only ${ROOTFS_PACKAGES}
+ run_privileged_heredoc <<'EOF'
+ set -e
+ ${@insert_isar_mounts(d, d.getVar('ROOTFSDIR'), d.getVar('ROOTFS_MOUNTS')) if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''}
+ ${HOST_APT_CMD} \
+ ${ROOTFS_APT_ARGS} \
+ -o Debug::NoLocking=1 \
+ --download-only ${ROOTFS_PACKAGES}
+EOF
}
ROOTFS_INSTALL_COMMAND_BEFORE_EXPORT ??= ""
@@ -421,16 +388,15 @@ ROOTFS_INSTALL_COMMAND += "rootfs_install_pkgs_isar_download"
rootfs_install_pkgs_isar_download[weight] = "50"
rootfs_install_pkgs_isar_download[isar-apt-lock] = "acquire-before release-after"
rootfs_install_pkgs_isar_download() {
- # Command apt-get install do not cache packages from local repos
- # We can obtain non cached package URIs by recalling install command here
- # No need to export those files to dl_dir, so we can run it right after
- rootfs_cmd --bind "${ROOTFSDIR}/var/cache/apt/archives" /var/cache/apt/archives \
- --chdir "/var/cache/apt/archives" \
- ${ROOTFSDIR} \
- -- /usr/bin/sh -c 'apt-get ${ROOTFS_APT_ARGS} --print-uris ${ROOTFS_PACKAGES} | \
- sed -n "s|^.file:\(/[^'\'']*\.deb\). \([^ ]*\.deb\).*|\1 \2|p" | \
- sed ":a; s|^\([^ ]*\)%|\1\\\\x|; ta" | \
- while read -r path name; do cp -n "$(/usr/bin/printf "%b" "$path")" "$name" ; done'
+ run_privileged_heredoc <<'EOF'
+ set -e
+ ${@insert_isar_mounts(d, d.getVar('ROOTFSDIR'), d.getVar('ROOTFS_MOUNTS')) if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''}
+ ${HOST_APT_CMD} \
+ ${ROOTFS_APT_ARGS} --print-uris ${ROOTFS_PACKAGES} | \
+ sed -n "s|^.file:\(/[^'\'']*\.deb\). \([^ ]*\.deb\).*|\1 \2|p" | \
+ sed ":a; s|^\([^ ]*\)%|\1\\\\x|; ta" | \
+ while read -r path name; do cp -n "$(/usr/bin/printf "%b" "$path")" "${ROOTFSDIR}/var/cache/apt/archives/$name" ; done
+EOF
}
ROOTFS_INSTALL_COMMAND += "${@ 'rootfs_install_clean_files' if (d.getVar('ROOTFS_CLEAN_FILES') or '').strip() else ''}"
@@ -451,8 +417,7 @@ rootfs_install_pkgs_install() {
run_privileged_heredoc <<'EOF'
set -e
${@insert_isar_mounts(d, d.getVar('ROOTFSDIR'), d.getVar('ROOTFS_MOUNTS')) if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''}
- chroot "${ROOTFSDIR}" \
- /usr/bin/apt-get ${ROOTFS_APT_ARGS} --no-download ${ROOTFS_PACKAGES}
+ ${HOST_APT_CMD} ${ROOTFS_APT_ARGS} --no-download ${ROOTFS_PACKAGES}
EOF
}
@@ -472,7 +437,7 @@ rootfs_clear_initrd_symlinks() {
run_privileged rm -f ${ROOTFSDIR}/initrd.img.old
}
-ROOTFS_INSTALL_COMMAND += "${@bb.utils.contains('ROOTFS_FEATURES', 'generate-sbom', 'rootfs_capture_apt_state', '', d)}"
+ROOTFS_POSTPROCESS_COMMAND:prepend = "${@bb.utils.contains('ROOTFS_FEATURES', 'generate-sbom', 'rootfs_capture_apt_state', '', d)} "
rootfs_capture_apt_state() {
( cd ${ROOTFSDIR} && find usr/share/doc -name copyright -print0 ) | \
tar -cf ${WORKDIR}/${ROOTFS_APT_STATE} --zstd --sort=name \
@@ -485,6 +450,7 @@ rootfs_capture_apt_state() {
var/lib/apt/extended_states \
var/lib/dpkg/status
}
+ROOTFS_POSTPROCESS_COMMAND:prepend = "rootfs_redirect_isar_apt_to_target "
ROOTFS_INSTALL_DEPENDS ?= ""
@@ -583,8 +549,7 @@ cache_dbg_pkgs() {
ROOTFS_POSTPROCESS_COMMAND += "${@bb.utils.contains('ROOTFS_FEATURES', 'clean-package-cache', 'rootfs_postprocess_clean_package_cache', '', d)}"
rootfs_postprocess_clean_package_cache() {
- run_in_chroot '${ROOTFSDIR}' \
- /usr/bin/apt-get clean
+ run_privileged ${HOST_APT_CMD} clean
# remove apt-cache folder itself (required in case rootfs is provided by sstate cache)
run_privileged find "${ROOTFSDIR}/var/cache/apt" -type f \
\( -name '*.deb' -o -name '*.bin' \) -delete
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-12-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 12/13] bootstrap: do not include apt
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (10 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 11/13] rootfs: use host apt to install packages into rootfs 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
2026-10-02 14:49 ` [PATCH 13/13] bootstrap: do not add ca-certificates 'Felix Moessbauer' via isar-users
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
As we now use the host-apt to operate on the chroot, we don't need apt
inside it. If it is needed (like for the sbuild chroot), we just install
it into the rootfs later on.
Not having apt inside the chroot exposes packaging bugs, assuming that
it (or any of its dependencies) is available. To work around these, we
explicitly install the needed packages on a case-by-case decision.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
meta-isar/conf/distro/raspios-bookworm.conf | 2 ++
meta-isar/conf/distro/raspios-bullseye.conf | 2 ++
meta-isar/conf/distro/ubuntu-focal.conf | 3 ++
.../image-account-extension.bbclass | 1 +
meta/classes-recipe/sdk.bbclass | 5 ++-
.../isar-mmdebstrap/isar-mmdebstrap.inc | 32 ++-----------------
.../sbom-chroot/sbom-chroot.bb | 2 +-
.../sbuild-chroot/sbuild-chroot.inc | 1 +
8 files changed, 17 insertions(+), 31 deletions(-)
diff --git a/meta-isar/conf/distro/raspios-bookworm.conf b/meta-isar/conf/distro/raspios-bookworm.conf
index 7fc83b0f..92f89c34 100644
--- a/meta-isar/conf/distro/raspios-bookworm.conf
+++ b/meta-isar/conf/distro/raspios-bookworm.conf
@@ -19,6 +19,8 @@ DISTRO_MM_OPTS += "${MMAPTOPT_NOEXPKEYSIGN}"
DISTRO_BOOTSTRAP_KEYS = "http://raspbian.raspberrypi.org/raspbian.public.key;sha256sum=ca59cd4f2bcbc3a1d41ba6815a02a8dc5c175467a59bd87edeac458f4a5345de"
DISTRO_BOOTSTRAP_KEYS:arm64 = ""
+# workaround for missing depends to apt in raspbian-archive-keyring
+DISTRO_BOOTSTRAP_BASE_PACKAGES:append = " apt gnupg2"
DISTRO_KERNELS ?= "kernel kernel7 kernel7l kernel8"
diff --git a/meta-isar/conf/distro/raspios-bullseye.conf b/meta-isar/conf/distro/raspios-bullseye.conf
index a8b59c09..fb0ac423 100644
--- a/meta-isar/conf/distro/raspios-bullseye.conf
+++ b/meta-isar/conf/distro/raspios-bullseye.conf
@@ -20,6 +20,8 @@ DISTRO_MM_OPTS += "${MMAPTOPT_NOEXPKEYSIGN}"
DISTRO_BOOTSTRAP_KEYS = "http://raspbian.raspberrypi.org/raspbian.public.key;sha256sum=ca59cd4f2bcbc3a1d41ba6815a02a8dc5c175467a59bd87edeac458f4a5345de"
DISTRO_BOOTSTRAP_KEYS:arm64 = ""
DISTRO_BOOTSTRAP_BASE_PACKAGES:append = " usrmerge"
+# workaround for missing depends to apt in raspbian-archive-keyring
+DISTRO_BOOTSTRAP_BASE_PACKAGES:append = " apt gnupg2"
DISTRO_KERNELS ?= "kernel kernel7 kernel7l kernel8"
diff --git a/meta-isar/conf/distro/ubuntu-focal.conf b/meta-isar/conf/distro/ubuntu-focal.conf
index 155644c1..b6c3e442 100644
--- a/meta-isar/conf/distro/ubuntu-focal.conf
+++ b/meta-isar/conf/distro/ubuntu-focal.conf
@@ -12,3 +12,6 @@ DISTRO_GCC = "9"
DEBIAN_COMPAT = "12"
DEBIAN_STANDARDS_VERSION ?= "4.5.0"
+
+# workaround for missing depends in /usr/share/initramfs-tools/hooks/fixrtc
+IMAGE_PREINSTALL:append = " e2fsprogs"
diff --git a/meta/classes-recipe/image-account-extension.bbclass b/meta/classes-recipe/image-account-extension.bbclass
index dd70f2a3..8c7a3270 100644
--- a/meta/classes-recipe/image-account-extension.bbclass
+++ b/meta/classes-recipe/image-account-extension.bbclass
@@ -140,6 +140,7 @@ def image_create_users(d: "DataSmart") -> None:
bb.process.run([*chroot, "/usr/bin/passwd", "--expire", entry])
+ROOTFS_PACKAGES += "passwd"
ROOTFS_POSTPROCESS_COMMAND += "image_postprocess_accounts"
image_postprocess_accounts[vardeps] += "USERS GROUPS"
python image_postprocess_accounts() {
diff --git a/meta/classes-recipe/sdk.bbclass b/meta/classes-recipe/sdk.bbclass
index 543df84b..b2bf01ed 100644
--- a/meta/classes-recipe/sdk.bbclass
+++ b/meta/classes-recipe/sdk.bbclass
@@ -42,7 +42,10 @@ SDK_PREINSTALL += " \
apt \
automake \
devscripts \
- equivs"
+ equivs \
+ apt \
+ passwd \
+"
# rootfs/image overrides for the SDK
ROOTFS_ARCH:class-sdk = "${HOST_ARCH}"
diff --git a/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc b/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
index 6135da4f..103d03bf 100644
--- a/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
+++ b/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
@@ -9,7 +9,7 @@ inherit bootstrap
inherit compat
inherit deb-dl-dir
-DISTRO_BOOTSTRAP_BASE_PACKAGES += "locales apt"
+DISTRO_BOOTSTRAP_BASE_PACKAGES += "locales"
DISTRO_BOOTSTRAP_BASE_PACKAGES:append:https-support = " ca-certificates"
BOOTSTRAP_TMPDIR = "${WORKDIR}/tempdir"
@@ -150,7 +150,7 @@ do_bootstrap() {
bbfatal "${DISTRO_ARCH} does not have a compat arch"
fi
fi
- bootstrap_args="--verbose --variant=minbase --include=${@','.join(d.getVar('DISTRO_BOOTSTRAP_BASE_PACKAGES').split())}"
+ bootstrap_args="--verbose --variant=essential --include=${@','.join(d.getVar('DISTRO_BOOTSTRAP_BASE_PACKAGES').split())}"
if [ -f "${DISTRO_BOOTSTRAP_KEYRING}" ]; then
bootstrap_args="$bootstrap_args --keyring=${DISTRO_BOOTSTRAP_KEYRING}"
cp "${DISTRO_BOOTSTRAP_KEYRING}" "${WORKDIR}/trusted.gpg.d/"
@@ -178,22 +178,7 @@ do_bootstrap() {
syncout='echo skip sync-out'
extra_setup="mount --bind '${REPO_BASE_DIR}' $base_apt_tmp"
extra_extract="$syncout"
- # save mmdebstrap tempdir for cleanup
- extra_essential="mkdir -p \$1/$base_apt_tmp && \
- echo \$1 > ${WORKDIR}/mmtmpdir && \
- mount -o bind,private '${REPO_BASE_DIR}' \$1/$base_apt_tmp"
- # replace base-apt mount in tmp with /base-apt mount
- extra_customize="sed -i \"s|copy://$base_apt_tmp|file:///base-apt|g\" \
- \$1/etc/apt/sources.list.d/*.list && \
- mkdir -p \$1/base-apt && \
- mount -o bind,private '${REPO_BASE_DIR}' \$1/base-apt && \
- chroot \$1 apt-get update -y \
- -o APT::Update::Error-Mode=any \
- ${@'-o APT::Sandbox::User=root' if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''} && \
- chroot \$1 apt-get install -y dpkg && \
- umount \$1/base-apt && \
- umount \$1/$base_apt_tmp && \
- umount $base_apt_tmp && rmdir \$1/$base_apt_tmp"
+ extra_customize="$syncout"
else
# prepare dl_dir for access from both sides (local and rootfs)
deb_dl_dir_import "${WORKDIR}/dl_dir" "${BOOTSTRAP_BASE_DISTRO}-${BASE_DISTRO_CODENAME}"
@@ -210,15 +195,6 @@ do_bootstrap() {
"${WORKDIR}/dl_dir/var/cache/apt/archives/"'
extra_setup="$syncin"
extra_extract="$syncout"
- # prefetch apt debs because mmdebstrap will clean them on next stage
- extra_essential='apt-get install apt -y -d \
- -o Dir::State="$1/var/lib/apt" \
- -o Dir::Etc="$1/etc/apt" \
- -o Dir::Cache="$1/var/cache/apt" \
- ${@'-o APT::Sandbox::User=root' if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''} \
- -o Apt::Architecture="${BOOTSTRAP_DISTRO_ARCH}" \
- ${@get_apt_opts(d, '-o')}'
- extra_essential="$extra_essential && $syncout"
extra_customize="$syncout"
fi
@@ -255,11 +231,9 @@ do_bootstrap() {
--setup-hook='upload "${WORKDIR}/chroot-setup.sh" "/chroot-setup.sh"' \
--setup-hook='chmod a+rx "$1/chroot-setup.sh"' \
--extract-hook="$extra_extract" \
- --essential-hook="$extra_essential" \
--customize-hook="$extra_customize" \
--customize-hook='sed -i "/en_US.UTF-8 UTF-8/s/^# *//g" "$1/etc/locale.gen"' \
--customize-hook='chroot "$1" /usr/sbin/locale-gen' \
- --customize-hook='chroot "$1" /usr/bin/apt-get -y clean' \
--customize-hook='echo nameserver 127.0.0.1 > "$1"/etc/resolv.conf' \
--customize-hook='echo isar > "$1"/etc/hostname' \
${@'--skip=output/dev' if d.getVar('ISAR_CHROOT_MODE') == 'unshare' else ''} \
diff --git a/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb b/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb
index 4727efe4..2f5450ee 100644
--- a/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb
+++ b/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb
@@ -21,7 +21,7 @@ DEPENDS:append:bookworm = " python3-cyclonedx-lib"
DEPENDS:append:noble = " python3-cyclonedx-lib"
DEPENDS += "python3-debsbom python3-spdx-tools"
-SBOM_IMAGE_INSTALL = "python3-debsbom python3-spdx-tools python3-cyclonedx-lib"
+SBOM_IMAGE_INSTALL = "python3-debsbom python3-spdx-tools python3-cyclonedx-lib lz4"
ROOTFSDIR = "${WORKDIR}/rootfs"
ROOTFS_PACKAGES = "${SBOM_IMAGE_INSTALL}"
diff --git a/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc b/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
index ae9e0e76..8414f4b8 100644
--- a/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
+++ b/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
@@ -54,6 +54,7 @@ SBUILD_CHROOT_PREINSTALL_COMMON = " \
${@ 'ccache' if bb.utils.to_boolean(d.getVar('USE_CCACHE')) else ''} \
devscripts \
equivs \
+ apt \
"
SBUILD_CHROOT_DIR = "${WORKDIR}/rootfs"
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-13-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread* [PATCH 13/13] bootstrap: do not add ca-certificates
2026-10-02 14:49 [PATCH 00/13] More build time reductions 'Felix Moessbauer' via isar-users
` (11 preceding siblings ...)
2026-10-02 14:49 ` [PATCH 12/13] bootstrap: do not include apt 'Felix Moessbauer' via isar-users
@ 2026-10-02 14:49 ` 'Felix Moessbauer' via isar-users
12 siblings, 0 replies; 14+ messages in thread
From: 'Felix Moessbauer' via isar-users @ 2026-10-02 14:49 UTC (permalink / raw)
To: isar-users
Cc: cedric.hombourger, jan.kiszka, quirin.gylstorff, Felix Moessbauer
As we now use the host apt for all operations, there is no need to have
the ca-certificates in the rootfs. Drop it and remove related
infrastructure. If it is desired to have it in the generated rootfs,
just add it using IMAGE_PREINSTALL.
As sbuild might require it (e.g. if the apt sources use https), we just
unconditionally add it.
Signed-off-by: Felix Moessbauer <felix.moessbauer@siemens.com>
---
.../recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc | 12 ------------
.../recipes-devtools/sbuild-chroot/sbuild-chroot.inc | 1 +
2 files changed, 1 insertion(+), 12 deletions(-)
diff --git a/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc b/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
index 103d03bf..4a99fdb9 100644
--- a/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
+++ b/meta/recipes-core/isar-mmdebstrap/isar-mmdebstrap.inc
@@ -10,7 +10,6 @@ inherit compat
inherit deb-dl-dir
DISTRO_BOOTSTRAP_BASE_PACKAGES += "locales"
-DISTRO_BOOTSTRAP_BASE_PACKAGES:append:https-support = " ca-certificates"
BOOTSTRAP_TMPDIR = "${WORKDIR}/tempdir"
DEPLOYDIR = "${WORKDIR}/deploy"
@@ -31,17 +30,6 @@ MMOPTS ?= ""
DISTRO_BOOTSTRAP_KEYRING = "${WORKDIR}/distro-keyring.gpg"
-def get_distro_have_https_source(d):
- return any(source[2].startswith("https://") for source in generate_distro_sources(d))
-
-def get_distro_needs_https_support(d):
- if get_distro_have_https_source(d):
- return "https-support"
- else:
- return ""
-
-OVERRIDES:append = ":${@get_distro_needs_https_support(d)}"
-
def get_apt_opts(d, param):
opts = []
retries = d.getVar('ISAR_APT_RETRIES') or "3"
diff --git a/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc b/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
index 8414f4b8..7ddf7b46 100644
--- a/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
+++ b/meta/recipes-devtools/sbuild-chroot/sbuild-chroot.inc
@@ -55,6 +55,7 @@ SBUILD_CHROOT_PREINSTALL_COMMON = " \
devscripts \
equivs \
apt \
+ ca-certificates \
"
SBUILD_CHROOT_DIR = "${WORKDIR}/rootfs"
--
2.55.0
--
You received this message because you are subscribed to the Google Groups "isar-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/isar-users/20261002144936.246628-14-felix.moessbauer%40siemens.com.
^ permalink raw reply [flat|nested] 14+ messages in thread