From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Tue, 24 Feb 2026 12:36:18 +0100 X-Sieve: CMU Sieve 2.4 Received: from mail-dl1-f56.google.com (mail-dl1-f56.google.com [74.125.82.56]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 61OBaGnf028835 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Tue, 24 Feb 2026 12:36:17 +0100 Received: by mail-dl1-f56.google.com with SMTP id a92af1059eb24-12721cd1a2asf24819404c88.1 for ; Tue, 24 Feb 2026 03:36:17 -0800 (PST) ARC-Seal: i=3; a=rsa-sha256; t=1771932970; cv=pass; d=google.com; s=arc-20240605; b=P4BLQM5+QQFLjJfMzOspwMorZ5HsCz35uIVpMP1mBYS6oIPlfjR+rNKa83hwnQIxWy UjByenJ7YRN/RUUXOFK+k2jQMMg8QWU+1BhHl4gAkYsvt4NsTQtdNJV6uH0YoDZu909V cqbHu4Pk/vThdjZosq7AfJIRxZuPm8ZXNlR8hYs5mat82/fXYNrHGo++TgfDplpCNGh4 RIpZZh7ZJwgORJe2j1P9KuvpsHYoeN4SfOa4sQNo9UNf7wuRExZXe8IGtjy+4dW0dPJR gbWbPcclRCwIN3zr/wDzUQpBr3uIwpJ9HOpY/eQxdzwcKm9uOAqJquQI897xqi1VPHY+ DO/A== ARC-Message-Signature: i=3; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:dkim-signature; bh=NOoJN27y+o/bF0d+fgZ67TFRwQ2VmbpI5h9rmsVc5IA=; fh=VZxBVDLBxf3xK8bW5QTzXbvqCon3XYA3Kzz3AvoOjjo=; b=AEcyW3hN5qXBITv0EE2m2IB1/xpJ9ixOx4amboL8VHP8Dhna6gbl8rcVXM5hT92uYf /cQtd1Dp02avvnTmBA+rRvFb+VOvLIGUpm47VwGk1QnP8HVjuzARGxy4gcDtgvLTmyrT W0vK52MtRTB2AFUjIoVXNdPt1/6S1wdQdW6HYT1TIZqO0rLFNFQsHDsH5Jfp/v/cfAu8 O5mqIefmfCXBAaOBgPjNq5Xr+rxqsIM+jZH5PnXbbJnXH9ySA+eD3DD6FU8XN7cQw6VX xgYuPiEETbMOPn1UvNXlViCIHxma2ioQZD1rfgh83dFPMUB3qG5QlJu2T+Y3FvF6hTje +itw==; darn=ilbers.de ARC-Authentication-Results: i=3; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=OFdm2sR2; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c207::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1771932970; x=1772537770; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:from:to:cc:subject:date:message-id :reply-to; bh=NOoJN27y+o/bF0d+fgZ67TFRwQ2VmbpI5h9rmsVc5IA=; b=tj5Y6NQ/d/rj6y3gvbFibxXLX1RUbKsxVBVmbDaYLBJIiwcNhvq4oSplGQXLluGk6c 06UXSb+xKrdEUnDO62S1e0dv58oHSWXz0dNHlW0PWP18VwsIpMBusZB9CdXIC8cpVOwS uAlDk1mz7DJCgnBo7ckkl5rrsHV/ZjdZb067o11rRDu5sPWWE+fcD8MtiWS2wxmmunJw XvBJgcsEk8wK2OsBXgFuLC7IQj4oAE6lCC4pZf6mDjfYKiHFf/ozkEKozizmW+w0MmXL fXyYOYFxlC5zB/29ryk73Ghsx8bZ4wwPoFB/ET4X9MDUs0TqnrfiPhOIB5/+j2DvT/29 3WPw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1771932970; x=1772537770; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence:reply-to :x-original-authentication-results:x-original-sender:mime-version :content-transfer-encoding:content-id:user-agent:content-language :accept-language:in-reply-to:references:message-id:date:thread-index :thread-topic:subject:cc:to:from:x-beenthere:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=NOoJN27y+o/bF0d+fgZ67TFRwQ2VmbpI5h9rmsVc5IA=; b=QVfNh7tGa/QzGYLxxbIilPK+7clkNsH6w41M0Vcy14oAay0dakxfBGFcsVPcgqEiQO lrjWctEX1QeuaAwATf+9NAivNs1XaBYtcuGbZ8CYpLlz5ItC8ykIEK787pmsvwS/q9/R pMCfSH4zAARDMqaNtHpUF9k5kVMtxhT6Ju56t53BEAC3TJAecGbuREk1qNliqddefKvL ksIz1xfw0qbGU/Fl8n8EQaqWEF3qSNS153Qc1O29JAwmkzRRxAHxs929whoBRkuy9iOw IC29MS5kGyOh3BPYW85rE1cJQVdLK4i9Rtb/N2M3KPBqurDFieqEyG/0+RzJ4LPgj2Ks FhEg== X-Forwarded-Encrypted: i=3; AJvYcCVJVGk2tPyvc9fd3WltVM/lNN/lMNjdexHhQ1I8VB1Sb8ER2EqHzXs8S9whNMF/DDnGlV+f@ilbers.de X-Gm-Message-State: AOJu0Yym0UG1XspMUJr6DkOaDp484QqUibOAa5OvUlMCmlPyuKOdh4Kc kLGtE077Zhp+Jt8Y4CqNLK1ErPSIbgrzddEzM52THAFN20xe85K2gj1b X-Received: by 2002:a05:7022:f83:b0:127:5cda:fb7d with SMTP id a92af1059eb24-1276acb3885mr6046895c88.6.1771932970242; Tue, 24 Feb 2026 03:36:10 -0800 (PST) X-BeenThere: isar-users@googlegroups.com; h="AV1CL+EWtWT+2ucijhYXsPcG+l/VEyyzhaIDYwsNhOv44M+0Ug==" Received: by 2002:a05:7022:1e17:b0:120:568e:18cf with SMTP id a92af1059eb24-1273c39ee05ls6753563c88.3.-pod-prod-08-us; Tue, 24 Feb 2026 03:36:08 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCXdjKfIt9que9Qyd+7P4OirsEnAI68AmtEN2VZtIHEzAdkeUMLEM7mHaIGRJ6WIfBKjWyN0La6nwAn3@googlegroups.com X-Received: by 2002:a05:7022:6b94:b0:11a:126f:ee7d with SMTP id a92af1059eb24-1276ad41568mr4591122c88.35.1771932968257; Tue, 24 Feb 2026 03:36:08 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1771932968; cv=pass; d=google.com; s=arc-20240605; b=IETMB1hiHUGiisz2VlxvysZnfqq/Z0MGemIRgsMmUmRITMb5P3aq124OzCcvJWP+X7 7V02SS0WiO8guBXv0lTEIFCZc1t6wL7H8RwEbKBhd8rEo8MCdVLzFHGam5VR520rIQpT Q1OSeM6jrvLkZXSL/fYD8dAMwYHhbrWIDHzMdo1gswUFpZHJp7lSAsT5FPEIwVFT3nBo 4TXViyR3fQhYXEyl2yjWVCHUjuzPu7gSn6U9zVDF14f+HQ/RCW9tqrtFgtO+pBWHruSw a/nyTgJ/bUdkx5yPpssWnipuOXVmMsVKYl0K74g+NJ9hPoP6EhW6gds07dSPs1U+hBE7 zFSA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=mime-version:content-transfer-encoding:content-id:user-agent :content-language:accept-language:in-reply-to:references:message-id :date:thread-index:thread-topic:subject:cc:to:from:dkim-signature; bh=FhqxNeg/Fihyqt1Yd8vAxHyAiMxGgd86IsYGfIhecUU=; fh=TCZeE2WsN4pnRo5poegZTKzoPPPvpqNUN6q8cInAIOE=; b=Ux9YVzU/FXQGxLyrt0dBVmhIaNXVb8ao9jq+pIAMyK5M18+gB8DQmJNeHxzK30u7u6 VbjaD6f3J8xJdSqX8xSs0UJgcWiXfmf28GQMaRIB9TmwZIWyQxPQSYo1+CX4eYoGqyjp Ig7SC2tiYYJrEh/HtyOHs7jN8qNndQxdioNYoHkciZkNqBVenUKqDuH0MnvauZsdo4hY t7Nxq3tABMw34oriPaV2zkoqXmzWi9GyFP9c7tKw5/d4RmHXaHQsA0UGJ0tBRHlCpYZ0 NroTVhK10WQRAUb4m1o/wf0LcWtE+/rN0ZooH1vIO0h01DfOb6AI96yIBn/qRGFktgPO MHcg==; dara=google.com ARC-Authentication-Results: i=2; gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=OFdm2sR2; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c207::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com Received: from MRWPR03CU001.outbound.protection.outlook.com (mail-francesouthazlp170110003.outbound.protection.outlook.com. [2a01:111:f403:c207::3]) by gmr-mx.google.com with ESMTPS id a92af1059eb24-1276af6c2b0si334123c88.7.2026.02.24.03.36.07 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 24 Feb 2026 03:36:07 -0800 (PST) Received-SPF: pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c207::3 as permitted sender) client-ip=2a01:111:f403:c207::3; ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=vsYzPSxljPfTatHRnmQSuMXWiEKPtAqVnhnI0hV9e68Bj1z6UNz/FkdWlzl3aGC2mY73dVD+yq5SplGXv8L3t1Pajs30hbjvbnNsc/h9/VjwP9Ztl7xYvzy/bhGkLoL0Kbb9W/+5veWuYqPMoDQ+CQcdLJx8GLcCB7Y9dxX5aPdo/jmp5pJGEZmGUCE4NG3tJ3dnEJkpdkdFLGqzSSh4b8F1JAv3qjRz36X4CtjzJWvmupVEP82LfIEN+4W0gCw4W386IxbZloUm7ulEgXmokkPv6522hFRiHjKM1frfeowvL1ODlBAPBJyLYZ8Ua17nKA2kxNqAXhG4vuVQ7EXxIA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=FhqxNeg/Fihyqt1Yd8vAxHyAiMxGgd86IsYGfIhecUU=; b=Y1kS8QWGqEZnPnEee2+83Pyb8HIiYuRkZY+hrYZ1kA+wiAwa+tzFwsVJSiIXfJhWUl64EuAu6/GLLn64tfgCzV+/75xAnWCIBOJm31S+XD2So3XjSUsqJUDQTn5wnRA2DdSSV7FGeYbv8Aj/o90Cf0k2efPV9TG70ZpgdAPYXoX2ZKz/GuYoBikcqPsCSLcAMF+MhjHUzCeBkUazatkdrTEoZG4AyKI/rmWjf/Xqnm+a1dqbrUaakDgGlY0w8g3U4JALnQCbE1G+6LjENJf7qwiC0S9Ib1B83TP8KY6680jNv6g+xi2MJsNufnukUq48R7pgXjKenAW6fbGJJXc0jA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=siemens.com; dmarc=pass action=none header.from=siemens.com; dkim=pass header.d=siemens.com; arc=none Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:10:47f::13) by AS8PR10MB7160.EURPRD10.PROD.OUTLOOK.COM (2603:10a6:20b:612::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9632.16; Tue, 24 Feb 2026 11:36:04 +0000 Received: from DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::9412:cd7f:3f72:92ab]) by DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM ([fe80::9412:cd7f:3f72:92ab%3]) with mapi id 15.20.9632.017; Tue, 24 Feb 2026 11:36:04 +0000 From: "'MOESSBAUER, Felix' via isar-users" To: "ubely@ilbers.de" , "isar-users@googlegroups.com" CC: "Gylstorff, Quirin" , "Kiszka, Jan" Subject: Re: [RFC v2 19/19] use copy of sbom-chroot for sbom creation Thread-Topic: [RFC v2 19/19] use copy of sbom-chroot for sbom creation Thread-Index: AQHcoozK7+EbwGMQo0C+VbP7466JJrWRrNcAgAARkoA= Date: Tue, 24 Feb 2026 11:36:04 +0000 Message-ID: <32b1cfc2bd4136098ccc3e75b756d02b434a4d29.camel@siemens.com> References: <20260220171601.3845113-1-felix.moessbauer@siemens.com> <20260220171601.3845113-20-felix.moessbauer@siemens.com> <7d85cb9a26928e4dd0a3827a13e02858cfb61b60.camel@ilbers.de> In-Reply-To: <7d85cb9a26928e4dd0a3827a13e02858cfb61b60.camel@ilbers.de> Accept-Language: de-DE, en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: user-agent: Evolution 3.56.2-8 x-ms-publictraffictype: Email x-ms-traffictypediagnostic: DU0PR10MB6828:EE_|AS8PR10MB7160:EE_ x-ms-office365-filtering-correlation-id: 89329e9c-c9b5-4b4c-05e4-08de7398e4cf x-ms-exchange-atpmessageproperties: SA x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0;ARA:13230040|366016|1800799024|376014|38070700021; x-microsoft-antispam-message-info: =?utf-8?B?ekQyV3lhMmpMTlBnbHk2STQ5WFVRTmUwUGFEaUhKYmRicUF4a01FTDd0Y1My?= =?utf-8?B?dGNhYk1nd2MzRGhIa1QvbE5TbENrSnVHWjdZTkF4NTl0OSt6aVJ4VlpYeTcy?= =?utf-8?B?b1hEb3JKaFZtUTRKaEtoWEhqcXZ5dmFXbG5aR1pSdzROUWVLY0xzTWZMNjhW?= =?utf-8?B?aXRBWTFGQmpEaVNrWWZqLytHTEdVYUppc3ZLMnByZk9NUmNrNVRkQ1J4NWFs?= =?utf-8?B?UVV1bDMzTENiOXU1blpiZ0d2WmdNcVJOWHlWTi9pTVNOaE5yRnlzU3lyWHFz?= =?utf-8?B?ZTlXODBESTVmOStCYkh4THlKZXIrVytZYnMrSHhvd0lNbFZOaWZVL1VGTFk4?= =?utf-8?B?RHNwU1NBYk9TakZhV0pCNUhXRlFCS1B3MVhUQ3JmMU5aeWM4U0tXRlF6TGw2?= =?utf-8?B?dGljMGNGUlFjcmJGREFMWWJzUWtwQjMyVFFsUkR4WTFweTl6YmNXdXN3b1hm?= =?utf-8?B?anFxSGxlVmQ3bk5uUHd1YjRLZXRFUzdVV0xHdHNDY2tlMmNJT2lnVkNqS0FD?= =?utf-8?B?MVRPYmNsbVZIcFF5akpzdVlOeW94bjhvbzVkOEduYnR6MDdvRjdlYUhrNGdJ?= =?utf-8?B?K25YdVB6YXR3V0ZtbVRaYzAzK3docXAzditsdFdKdDRkR2VSbEVEVlRXTUN5?= =?utf-8?B?ellCZjZwOS9RR1B0alQ1NUpYdFZFSzhxTlUxMSs0bXd0Sml0TzFDYjZkNXN3?= =?utf-8?B?WVZhdjdlOHgvTmM2YzJ6QjBXOUlYejAzNGYwQTNLQmZpZm9ybmFaZVVJTUhJ?= =?utf-8?B?Z0ZnMENPNzJZZ1RCNTBXUEpnLzJGUUxaSmlHNW8yMVdmakNTWnZnaitQRjVi?= =?utf-8?B?VldPODd2Z1l1Y3Q5dG1zczNYdTl6RGduLzJ5NkFTZW9LVTZ1MEloUmY2eGY3?= =?utf-8?B?cHUxTmtWcEdkeVNhVmo5Q0JlWldPRktkYTdCYlFmZmViYnRBSTBZbVB0Z0w2?= =?utf-8?B?ZEZyNHAvZkxDWEpYRWkzdHBHdlFSRXBKQ0plYm1KMnhFcnZ1VS92SGs2dVcx?= =?utf-8?B?V0hHenVrNWJaM09aVzZPY3IyU3ZrWlB3d3VqZzcvUHp3N1JyM25MQUFtNUIr?= =?utf-8?B?UlI2NzE3YVA2RjkrZERXclFnbS9taFFHa3hVZkdCWlJvdmZ3djRwOHBzTHlZ?= =?utf-8?B?R3hNdTdQcnpFQUxvTmNnNDRYRUlGYkNjdXZ5MUd3N3hhZ1RVYUpYa0M3MW5G?= =?utf-8?B?QmZEb1QzTjB1KzcxbDhBSWd4dE1qTC9uMDNtK3Jid2Y5UnhZL1ptaFZFMnoy?= =?utf-8?B?WDA2UXp5SHNVdUxrVWQ0QWFFVmVTMWNwTEgrNjBUb0VXbG1UeTQ3S0ROK1J2?= =?utf-8?B?L3drVzI4a21qMlNwOGI3MStRQ1k3cUFqSWtBNWRNRkpYdU9BNkkrMHBMRjNt?= =?utf-8?B?TncyVkMrN0lSVzEvM1lqdDJxZjJJV25seFpRSG84ZFU4Zk1GZ0EvUHExRDhM?= =?utf-8?B?c09TZFpxT0d6WlZpQzVMNmNTd0szNElSdjRrRHVEdk1oZXptRG1hcW9jL3JC?= =?utf-8?B?bjVOc3VmQVBWbXBFemFtTlFmVFc2M1pqaXNGcmFvZzEzOGRURDlabnBRQ2ZB?= =?utf-8?B?NUowc05PR1RpUUNoQzBlVllUSG5KVUY1bEhhYlU4ZysvY0h3c0hjRFdxcm1V?= =?utf-8?B?VC9SZDE3T3Qra3ZIWG9zYW8zUUZDa3AzbTJlYnNYT0d3T2diWXRvNmNLbmVR?= =?utf-8?B?d0JyNUNDUjVEamlCVFdWVVg1SjBVWlNSdVpabUMwREM2RFhPMy9UWEdxMWxD?= =?utf-8?B?V3Bna3NhQ3FFS1dkK1A2R2VlQzNLMWxTaEZyVFhLcnlyYkVab3JsSEs5K2tY?= =?utf-8?B?aVl3Rzl6WGlnQkxxeTlYTTRjNmt1Z1RaQXNENjk1am5GTFJPUkYxbGtQenN1?= =?utf-8?B?Smt6NUFJbkVsYnRGTGRkbGcvdk5yRWdvM1pmV1lqUlhKZkFldm0va29UemxJ?= =?utf-8?B?ZTJxZlQ4SlhrWDJsanRGMW1teTVxQVpYVkJILzBHbjhtbS9VOTlBV3RBbnhF?= =?utf-8?B?S1ppNW1Qd0F1TGZ0YnhBazNRTGJoN0JEbER1cDBFczFwbmlyeGpvS3drc2lq?= =?utf-8?B?cFFzUHRSNDhWZWlyN2dyUEZOOUtpWC9ETTBBUWVpdEthWXBDY2l4UFhvS29P?= =?utf-8?B?ZGlFbkpvLzdnREg0Q3VjK2hyOW9xUVJVUUFMcnFtV255NCtPYVRnUm8wdXZt?= =?utf-8?Q?QgC9hcEZy8y0G0KGGAhir8w=3D?= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM;PTR:;CAT:NONE;SFS:(13230040)(366016)(1800799024)(376014)(38070700021);DIR:OUT;SFP:1101; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?utf-8?B?MzV1c0lrcFUrS2pwVi9TZENaR1BheEJHcmsxYW1OaG12WmZaQ2RLa2pVdko0?= =?utf-8?B?VTY5MzQ0TmI5SzZDdUVpOG0vclIvOHlTT0l6MGV2NFZGMUs1dnlNVzdGRW80?= =?utf-8?B?SFVkZytTWGVzRVlyN211czRyUHBQNEM2UFlTdEMrZklxREZDa2NGNU1qTlM3?= =?utf-8?B?THE5SCt3Wng5Q1RDbWl1Mk9qcU8vWXJHRlQ1UGpaUG5KbE1kb001WkRVckZj?= =?utf-8?B?Ym9TRjZyT2JTaTRHM3VFSTB5ZFpHMmpMZ3RlM3lWMzBrWndIeU1QQStoWHg5?= =?utf-8?B?WWtTM2JneDQ2V3hnSXQ1ODJXRTA4L2JtdE1sT2RjZS9WRzU3WlZIRE1QQ205?= =?utf-8?B?bUVwUzhydzhuTXV2OThmSkx4Mk1YeXNsRmxDV2xjWUNGSEJhckxraDFYUEg5?= =?utf-8?B?QWNialhmTEVyYVlmYTRvYjRYdDJWbjJqck90TmZnQTdOdzdDakxMajBGbml4?= =?utf-8?B?b0NwNjBOQmJJTlcraytaWEF6STBNbDdUZ2xMSlN5MDlzN1ZXekk0SFovbWlt?= =?utf-8?B?c3RHSmlEdW5ocjFiUHVWQS96S0UramluTjhPbm1iT1UwbjY4d3pyaWNtMTNS?= =?utf-8?B?NW41QWlRdmw0VzlFT1JyQnQ4RlA4b3JaSWRHb2lQQXdlZ0xQdi9XL1h2RXRt?= =?utf-8?B?K1VVM3l2OVNVcW4rWDRxUFlVTk9oTmNkSnBRNVZGMEtCbTNnVzdPU1RqVWJO?= =?utf-8?B?elhWSmVOaUduU1czSjVLMU03Mi9ONVdCWjJzMi9uakF1VDlJbHVKYldkSUxs?= =?utf-8?B?VWFvYmhuZlhZYURiRnQzU3E3ckZBM05tZm9zS3NGSkx0ZlZBOTNQQlpjaTJu?= =?utf-8?B?QWVRWGIyNVB6Rm5rMGVFMjFRdjVqZmxoUEJEbEt4aEpUTG1abTNRd2FzT0Nl?= =?utf-8?B?Ym91RUwveXZzMlVmdlJ4cGU4UjV4dCtsZis4OC9saXQzNjMzeEg4eHhRQk5p?= =?utf-8?B?YjRhU2JKQXAremE3aHg2dDlpelJ6cnI5MEJQSXNFV3dERVJBZUVuQXpjRGVi?= =?utf-8?B?REJsdnkvY1NPMG05WTUwanJUSlU1VVFYYXNJejN4bHBCQ1FwRlBLM0pOZU5N?= =?utf-8?B?Y3o1Qlk2cjdJZzFiVHVHazlJU0JRZmtrNzY2OFc4YmVVd2tTeHlxM24vWDJO?= =?utf-8?B?ZkxjS0NjTmpRMVgzWUhTbkFGMU5oL0dzSS9LTE1qUnNGbjZWSStjcGNjVVNi?= =?utf-8?B?NlNUbGZUTHVManFQWWdOS3dVNG5JZGZCS2d2aDBIQVhpcWdVMlk1amxZR2JY?= =?utf-8?B?VTNVdTZCTEpTVDVkdjc4bGdvRDltb1hnWjNCcGxtSG1UbHVLL3ZsdlFsVGFM?= =?utf-8?B?dzIzbWlMTWhNbTlEbmxLSTBUZk8xOTJJUEdhNGhaM1hWNmFIZDZ6UzJoNWlF?= =?utf-8?B?eHlvK3pQQUo3Zjc5UDBJNThyRlh1MEJkUGJEdGpqbGRLUHlQSnU1VVZnaVVw?= =?utf-8?B?cUdEcUhLbWNxY0JVTzJWM1FVTEdhYThtbGZDMTdrajk0OEsxUEhRRW1yQm9F?= =?utf-8?B?ZXRJVHBpVllNcmNidlhNRXBMVFAzNDkrWVBvMXBqVThOMGxVV3liNFRMcmhV?= =?utf-8?B?OXhEa2Vsbm9nQXdDWDIrcVY0eFduc2NYM1d2RDQ4L1NpclNRRS9Td0trUkpx?= =?utf-8?B?QlI3TkU2YktzYm5pZm0xMjdRTkNqT2wzNkY1dUZtMGRoSlJzU2dqWGl0RFVr?= =?utf-8?B?WEt2Tmp0dWV6YXFwVW4xeU5oTWFLRkF2UXF1WThkVDZrbTZ3SjJwNjl6TG5l?= =?utf-8?B?LzNlcWlDMS9xblFxQXFJcXhwZ0RUdVovZlBwaVRDWTFmclNiSWRLejdYdmVw?= =?utf-8?B?MTJDZytpYm1oM2Fobk5vUndsZGhEOG84WEZpYWtPSU5EM3lOemJLTzU0YVZM?= =?utf-8?B?YS9ybHROWXZmUkVYZEdQdzFiSDluQU9vbTZWZVJ6TWM1aENuNkFOWXAzcmhL?= =?utf-8?B?TTVzeDRJSGVJS0ljekZsc25LaE5iYjJkSU1nZXM1VVJVR2lxZFd3ajBjb1Vp?= =?utf-8?B?U3NWWEVlYVpmUTZSTklFUi9iQUN4YVJ5MXIzdzc4a0tMUEJwUk9uaXJlaHhN?= =?utf-8?B?SmpOUkg1dzdIYkk3VFJ1NU5CSjBhRWFLb2xKZmlxTEtqOUhxQ1gxNWhzK0da?= =?utf-8?B?VnhKU25kbEx5bkxiUVVDRERXL2pZK0Vnb2tvdDVkS0dXS2hobVpKV2NJczlu?= =?utf-8?B?YTNWV3dHempkdkcyZ3dFWHd0UnhqYzJrTTJ5NnorSkZMNlB3OUZsUDJNQTBl?= =?utf-8?B?UFcxcHJBUzNiMVpyb2V0bUVZNGljUndLVS9icnMyMmE3MVlEM3dJMEN1Rktn?= =?utf-8?B?R2tNK0ZRNnpOQ1QxZ0ZsVzdHV0ZLYzdYdHJqbk9hZi9JazRKQkxrdXJWMmp3?= =?utf-8?Q?6YTQuSqUN9cXhS5JpYzlZ03bput8Y/58iXTYU?= Content-Type: text/plain; charset="UTF-8" Content-ID: Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-OriginatorOrg: siemens.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: DU0PR10MB6828.EURPRD10.PROD.OUTLOOK.COM X-MS-Exchange-CrossTenant-Network-Message-Id: 89329e9c-c9b5-4b4c-05e4-08de7398e4cf X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Feb 2026 11:36:04.4034 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 38ae3bcd-9579-4fd4-adda-b42e1495d55a X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: I/wLjJgerT57m/BYXD6aaSp2Wpn1TzGBpk/S2EjSCE+Mc9G6x6QhsHCsRKdbtZqHPvsYiNk3i7LoS84f2T+vjicw+ZQQNPBM/Wny+Tztf0w= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR10MB7160 X-Original-Sender: felix.moessbauer@siemens.com X-Original-Authentication-Results: gmr-mx.google.com; dkim=pass header.i=@siemens.com header.s=selector2 header.b=OFdm2sR2; arc=pass (i=1 spf=pass spfdomain=siemens.com dkim=pass dkdomain=siemens.com dmarc=pass fromdomain=siemens.com); spf=pass (google.com: domain of felix.moessbauer@siemens.com designates 2a01:111:f403:c207::3 as permitted sender) smtp.mailfrom=felix.moessbauer@siemens.com; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=siemens.com X-Original-From: "MOESSBAUER, Felix" Reply-To: "MOESSBAUER, Felix" Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Status: No, score=-4.9 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,MAILING_LIST_MULTI, RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: J9ixMK9MhJh7 On Tue, 2026-02-24 at 13:33 +0300, Uladzimir Bely wrote: > Hello Felix. >=20 > On Fri, 2026-02-20 at 18:16 +0100, 'Felix Moessbauer' via isar-users > wrote: > > We previously used the same sbom-chroot for generating the sbom of > > different root filesystems. This required to have a live copy of the > > sbom-chroot in the deploy dir, on which also was operated on. > > Further, > > this copy was left behind in the deploy dir. > >=20 > > We improve this by just storing a minimized tarball of the sbom- > > chroot > > in the deploy dir and extract that into the workdir of the rootfs. > >=20 > > Signed-off-by: Felix Moessbauer > > --- > > =C2=A0meta/classes/sbom.bbclass=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0 | 29 ++++++++++++++++- > > -- > > =C2=A0.../sbom-chroot/sbom-chroot.bb=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 | 11 ++++++- > > =C2=A02 files changed, 35 insertions(+), 5 deletions(-) > >=20 > > diff --git a/meta/classes/sbom.bbclass b/meta/classes/sbom.bbclass > > index e3d0e702..69c5d1b0 100644 > > --- a/meta/classes/sbom.bbclass > > +++ b/meta/classes/sbom.bbclass > > @@ -23,7 +23,8 @@ SBOM_SPDX_NAMESPACE_PREFIX ?=3D > > "https://spdx.org/spdxdocs" > > =C2=A0DEPLOY_DIR_SBOM =3D "${DEPLOY_DIR_IMAGE}" > > =C2=A0 > > =C2=A0SBOM_DIR =3D "${DEPLOY_DIR}/sbom" > > -SBOM_CHROOT =3D "${SBOM_DIR}/sbom-chroot" > > +SBOM_CHROOT =3D "${SBOM_DIR}/sbom-chroot.tar.zst" > > +SBOM_CHROOT_LOCAL =3D "${WORKDIR}/sbom-chroot" >=20 > This change also requires appropriate changes in at least image-tools- > extension.bbclass and imagetype_wic.bbclass, e.g.: Yes, I also found this later on and already fixed it. Will be part of the v3. Are you considering this patch relevant for the release? In this case I can just send the fixed version as a standalone patch on next. Just let me know. v3 also reworks the whole imaging part to require less (or ideally no) changes in downstream layers. Felix >=20 >=20 > diff --git a/meta/classes-recipe/imagetypes_wic.bbclass b/meta/classes- > recipe/imagetypes_wic.bbclass > index ebf3ce8e..34f2286e 100644 > --- a/meta/classes-recipe/imagetypes_wic.bbclass > +++ b/meta/classes-recipe/imagetypes_wic.bbclass > @@ -216,13 +216,16 @@ merge_wic_sbom() { > =C2=A0=C2=A0=C2=A0=C2=A0 TIMESTAMP=3D$(date --iso-8601=3Ds -d @${SOURCE_D= ATE_EPOCH}) > =C2=A0=C2=A0=C2=A0=C2=A0 sbom_document_uuid=3D"${@d.getVar('SBOM_DOCUMENT= _UUID') or > generate_document_uuid(d, False)}" > =C2=A0 > +=C2=A0=C2=A0=C2=A0 mkdir -p ${SBOM_CHROOT_LOCAL} > +=C2=A0=C2=A0=C2=A0 tar -xf ${SBOM_CHROOT} -C ${SBOM_CHROOT_LOCAL} > + > =C2=A0=C2=A0=C2=A0=C2=A0 cat ${DEPLOY_DIR_IMAGE}/${IMAGE_FULLNAME}.${bomt= ype}.json \ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ${DEPLOY_DIR_IMAGE}/${IN= ITRD_DEPLOY_FILE}.${bomtype}.json \ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ${WORKDIR}/imager.${bomt= ype}.json 2>/dev/null | \ > =C2=A0=C2=A0=C2=A0=C2=A0 bwrap \ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --unshare-user \ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --unshare-pid \ > -=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --bind ${SBOM_CHROOT} / \ > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --bind ${SBOM_CHROOT_LOCAL} /= \ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 -- debsbom -v merge -t $= BOMTYPE \ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 = --distro-name '${SBOM_DISTRO_NAME}-Image' --distro- > supplier '${SBOM_DISTRO_SUPPLIER}' \ > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 = --distro-version '${SBOM_DISTRO_VERSION}' --base-distro- > vendor '${SBOM_BASE_DISTRO_VENDOR}' \ >=20 >=20 > Without it, in my build this failed at wic stage (qemuamd64 target) > when attempting to bind-mount tar.zst: >=20 >=20 > bwrap --unshare-user --unshare-pid --bind > =C2=A0/work/build/tmp/deploy/sbom/sbom-chroot.tar.zst / -- debsbom -v mer= ge > -t spdx --distro-name ISAR-Debian-GNU-Linux-Image --distro-supplier > ISAR --distro-version 1 --base-distro-vendor debian --cdx-serialnumber > 4641ea56-9fce-4120-ae90-0784cd98d434 --spdx-namespace > https://spdx.org/spdxdocs-4641ea56-9fce-4120-ae90-0784cd98d434=C2=A0-- > timestamp 2024-03-04T18:14:11+03:00 - -o - >=20 > bwrap: Can't create file at /: Is a directory >=20 >=20 > > =C2=A0 > > =C2=A0# adapted from the isar-cip-core image_uuid.bbclass > > =C2=A0def generate_document_uuid(d, warn_not_repr=3DTrue): > > @@ -40,14 +41,25 @@ def sbom_doc_uuid(d): > > =C2=A0=C2=A0=C2=A0=C2=A0 if not d.getVar("SBOM_DOCUMENT_UUID"): > > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 d.setVar("SBOM_DOCUMEN= T_UUID", generate_document_uuid(d)) > > =C2=A0 > > +prepare_sbom_chroot() { > > +=C2=A0=C2=A0=C2=A0 create_chroot_parent_dir ${WORKDIR} > > +=C2=A0=C2=A0=C2=A0 run_privileged_heredoc <<'EOF' > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 set -e > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 mkdir -p ${SBOM_CHROOT_LOCA= L} > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 tar -xf ${SBOM_CHROOT} -C $= {SBOM_CHROOT_LOCAL} > > +EOF > > +} > > + > > =C2=A0generate_sbom() { > > -=C2=A0=C2=A0=C2=A0 run_privileged mkdir -p ${SBOM_CHROOT}/mnt/rootfs > > ${SBOM_CHROOT}/mnt/deploy-dir > > +=C2=A0=C2=A0=C2=A0 run_privileged mkdir -p \ > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ${SBOM_CHROOT_LOCAL}/mnt/ro= otfs \ > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 ${SBOM_CHROOT_LOCAL}/mnt/de= ploy-dir > > =C2=A0 > > =C2=A0=C2=A0=C2=A0=C2=A0 TIMESTAMP=3D$(date --iso-8601=3Ds -d @${SOURCE= _DATE_EPOCH}) > > =C2=A0=C2=A0=C2=A0=C2=A0 bwrap \ > > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --unshare-user \ > > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --unshare-pid \ > > -=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --bind ${SBOM_CHROOT} / \ > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --bind ${SBOM_CHROOT_LOCAL}= / \ > > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --bind ${ROOTFSDIR} /m= nt/rootfs \ > > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 --bind ${DEPLOY_DIR_SB= OM} /mnt/deploy-dir \ > > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 -- debsbom -v generate= ${SBOM_DEBSBOM_TYPE_ARGS} -r > > /mnt/rootfs -o /mnt/deploy-dir/'${PN}-${DISTRO}-${MACHINE}' \ > > @@ -59,8 +71,17 @@ generate_sbom() { > > =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0 --timestamp $TIMESTAMP ${SBOM_DEBSBOM_EXTRA_ARGS} > > =C2=A0} > > =C2=A0 > > +cleanup_sbom_chroot() { > > +=C2=A0=C2=A0=C2=A0 run_privileged rm -rf ${SBOM_CHROOT_LOCAL} > > +} > > + > > =C2=A0do_generate_sbom[dirs] +=3D "${DEPLOY_DIR_SBOM}" > > +do_generate_sbom[network] =3D "${TASK_USE_SUDO}" > > =C2=A0python do_generate_sbom() { > > =C2=A0=C2=A0=C2=A0=C2=A0 sbom_doc_uuid(d) > > -=C2=A0=C2=A0=C2=A0 bb.build.exec_func("generate_sbom", d) > > +=C2=A0=C2=A0=C2=A0 try: > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 bb.build.exec_func("prepare= _sbom_chroot", d) > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 bb.build.exec_func("generat= e_sbom", d) > > +=C2=A0=C2=A0=C2=A0 finally: > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 bb.build.exec_func("cleanup= _sbom_chroot", d) > > =C2=A0} > > diff --git a/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb > > b/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb > > index bf6d6683..fec1f502 100644 > > --- a/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb > > +++ b/meta/recipes-devtools/sbom-chroot/sbom-chroot.bb > > @@ -27,7 +27,16 @@ ROOTFSDIR =3D "${WORKDIR}/rootfs" > > =C2=A0ROOTFS_PACKAGES =3D "${SBOM_IMAGE_INSTALL}" > > =C2=A0 > > =C2=A0do_sbomchroot_deploy[dirs] =3D "${SBOM_DIR}" > > +do_sbomchroot_deploy[network] =3D "${TASK_USE_SUDO}" > > =C2=A0do_sbomchroot_deploy() { > > -=C2=A0=C2=A0=C2=A0 ln -Tfsr "${ROOTFSDIR}" "${SBOM_CHROOT}" > > +=C2=A0=C2=A0=C2=A0 # deploy with empty var to make it smaller > > +=C2=A0=C2=A0=C2=A0 lopts=3D"--one-file-system --exclude=3Dvar/*" > > +=C2=A0=C2=A0=C2=A0 ZSTD=3D"zstd -${SSTATE_ZSTD_CLEVEL} -T${ZSTD_THREAD= S}" > > + > > +=C2=A0=C2=A0=C2=A0 run_privileged \ > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 tar -C ${ROOTFSDIR} -cpS $l= opts ${ROOTFS_TAR_ATTR_FLAGS} . \ > > +=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 | $= ZSTD > ${SBOM_CHROOT} > > +=C2=A0=C2=A0=C2=A0 # cleanup extracted rootfs > > +=C2=A0=C2=A0=C2=A0 run_privileged rm -rf ${ROOTFSDIR} > > =C2=A0} > > =C2=A0addtask do_sbomchroot_deploy before do_build after do_rootfs > > --=20 > > 2.51.0 >=20 > -- > Best regards, > Uladzimir. --=20 Siemens AG Linux Expert Center Friedrich-Ludwig-Bauer-Str. 3 85748 Garching, Germany --=20 You received this message because you are subscribed to the Google Groups "= isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/= 32b1cfc2bd4136098ccc3e75b756d02b434a4d29.camel%40siemens.com.