diff --git a/.gitmodules b/.gitmodules index 0602afa..3371daa 100644 --- a/.gitmodules +++ b/.gitmodules @@ -57,3 +57,9 @@ path = platforms/nxp-conformance-yocto/doc/test-report-pdf url = https://github.com/savoirfairelinux/test-report-pdf branch = master +[submodule "platforms/nxp-imx93-yocto/sources/meta-clang"] + path = platforms/nxp-imx93-yocto/sources/meta-clang + url = https://github.com/kraj/meta-clang.git +[submodule "platforms/nxp-imx93-yocto/sources/meta-security"] + path = platforms/nxp-imx93-yocto/sources/meta-security + url = https://git.yoctoproject.org/meta-security diff --git a/platforms/nxp-imx93-yocto/README.md b/platforms/nxp-imx93-yocto/README.md index e8e35f5..aba6392 100644 --- a/platforms/nxp-imx93-yocto/README.md +++ b/platforms/nxp-imx93-yocto/README.md @@ -186,29 +186,29 @@ a tag; to reproduce that release, check out its tag before building. Use ## Release Profiles -The default release is `nxp-6.6.52-2.2.2`. +The default supported release is `nxp-6.6.52-2.2.2`. -Use the existing build command for the default release: +The experimental `nxp-6.12.34-2.1.0` release uses Walnascar / Yocto 5.2 and +the FRDM-i.MX93 machine provided by the main NXP `meta-imx` release. It also +uses `meta-clang` and `meta-security/meta-parsec`. The older +`meta-imx-frdm` layer is used only by the 6.6 release. -``` -ACCEPT_FSL_EULA=1 ./scripts/build.sh development -``` +Select a release with `--release`: -To select it explicitly: +```sh +ACCEPT_FSL_EULA=1 ./scripts/build.sh development \ + --release nxp-6.6.52-2.2.2 -- bitbake geisa-dev-image -``` -./scripts/setup-sources.sh --release nxp-6.6.52-2.2.2 ACCEPT_FSL_EULA=1 ./scripts/build.sh development \ - --release nxp-6.6.52-2.2.2 -``` + --release nxp-6.12.34-2.1.0 -- bitbake geisa-dev-image -The `nxp-6.12.34-2.1.0` profile is reserved for the newer NXP BSP. Its source -revisions and release-specific recipe changes have not yet been added, so it -cannot currently be selected for setup or build. +### Experimental 6.12 status -Source setup verifies the selected release against the checked-out submodule -revisions. It stops if a submodule contains local changes or does not match the -selected profile. +The 6.12 image builds with Linux 6.12.34 and U-Boot 2025.04. Walnascar support +includes unpack-path compatibility, explicit development image features, +TensorFlow Lite 2.19, and read-only application-container handling. Removable- +media validation is still required. Keep the known-good 6.6 eMMC image until it +passes. ## NXP License Acceptance @@ -237,17 +237,30 @@ build: ACCEPT_FSL_EULA=1 ./scripts/build.sh development -- bitbake -p -Deployment artifacts are written under: +Deployment artifacts are written under the selected release's build directory: + + /tmp/deploy/images/geisa-imx93/ + +For example: build-development/tmp/deploy/images/geisa-imx93/ + build-development-nxp-6.12.34-2.1.0/tmp/deploy/images/geisa-imx93/ The compressed disk image is named similarly to: geisa-dev-image-geisa-imx93.rootfs-.wic.zst -The deployment directory also contains the kernel, device tree, -installed-package manifest, license information, SPDX output, and related build -artifacts. +The deployment directory also contains the `.wic.bmap`, package manifest, +testdata JSON, image-manifest JSON, kernel, device trees, license information, +and SPDX output. + +The testdata JSON records the selected release, the GEISA Community repository +revision and dirty state, the expected and actual source revisions, and the +expected kernel and U-Boot revisions. `GEISA_SOURCE_REVISION` identifies the +GEISA Community repository revision, not an NXP layer revision. + +An image built with uncommitted repository changes records a dirty source state +and should be used for development validation rather than publication. For general sanity, you should calculate the WIC SHA-256 before writing the image: @@ -582,6 +595,15 @@ warning-log details. The script tolerates missing optional tools and reports the information available on the currently running image. +The output summarizes systemd state, LXC containers, network interfaces, and +available thermal readings. Missing optional tools and command failures are +reported rather than silently omitted. + +Set `GEISA_LXC_LS_PATH` to use a specific `lxc-ls` executable. + +The output is intended for simple status checks and quick diagnostics, including +use on smaller displays such as a 10-inch Raspberry Pi display. + Usage: geisa-system-state [--once] [--debug] diff --git a/platforms/nxp-imx93-yocto/build-configuration/templates/bblayers.conf b/platforms/nxp-imx93-yocto/build-configuration/templates/bblayers.conf index d468dd0..516c303 100644 --- a/platforms/nxp-imx93-yocto/build-configuration/templates/bblayers.conf +++ b/platforms/nxp-imx93-yocto/build-configuration/templates/bblayers.conf @@ -15,19 +15,4 @@ BBLAYERS ?= " \ @PLATFORM_ROOT@/sources/meta-arm/meta-arm-systemready \ @PLATFORM_ROOT@/sources/meta-freescale \ @PLATFORM_ROOT@/sources/meta-geisa-community \ - @PLATFORM_ROOT@/sources/meta-imx/meta-imx-ml \ - @PLATFORM_ROOT@/sources/meta-imx/meta-imx-bsp \ - @PLATFORM_ROOT@/sources/meta-imx-frdm/meta-imx-bsp \ - @PLATFORM_ROOT@/sources/meta-imx-frdm/meta-imx-sdk \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-webserver \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-gnome \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-filesystems \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-networking \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-initramfs \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-oe \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-xfce \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-python \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-multimedia \ - @PLATFORM_ROOT@/sources/meta-openembedded/meta-perl \ - @PLATFORM_ROOT@/sources/meta-virtualization \ " diff --git a/platforms/nxp-imx93-yocto/build-configuration/templates/local.conf b/platforms/nxp-imx93-yocto/build-configuration/templates/local.conf index 1a6fa48..ccf8840 100644 --- a/platforms/nxp-imx93-yocto/build-configuration/templates/local.conf +++ b/platforms/nxp-imx93-yocto/build-configuration/templates/local.conf @@ -140,13 +140,11 @@ DISTRO ?= "poky" # "eclipse-debug" - add Eclipse remote debugging support # "tools-profile" - add profiling tools (oprofile, lttng, valgrind) # "tools-testapps" - add useful testing tools (ts_print, aplay, arecord etc.) -# "debug-tweaks" - make an image suitable for development -# e.g. ssh root access has a blank password # There are other application targets that can be used here too, see # meta/classes-recipe/image.bbclass and # meta/classes-recipe/core-image.bbclass for more details. -# We default to enabling the debugging tweaks. -EXTRA_IMAGE_FEATURES ?= "debug-tweaks" +# Explicit development access features preserve the historical development image behavior. +EXTRA_IMAGE_FEATURES ?= "allow-empty-password empty-root-password allow-root-login" # # Additional image features diff --git a/platforms/nxp-imx93-yocto/releases/nxp-6.12.34-2.1.0.conf b/platforms/nxp-imx93-yocto/releases/nxp-6.12.34-2.1.0.conf index 750c03a..595d1de 100644 --- a/platforms/nxp-imx93-yocto/releases/nxp-6.12.34-2.1.0.conf +++ b/platforms/nxp-imx93-yocto/releases/nxp-6.12.34-2.1.0.conf @@ -1,12 +1,25 @@ RELEASE_ID="nxp-6.12.34-2.1.0" STATUS="experimental" NXP_BSP_VERSION="6.12.34-2.1.0" -YOCTO_SERIES="unresolved" +YOCTO_SERIES="walnascar" BUILD_DIR="build-development-nxp-6.12.34-2.1.0" MACHINE="geisa-imx93" DISTRO="geisa-dev" IMAGE="geisa-dev-image" -KERNEL_VERSION="unresolved" -KERNEL_SRCREV="unresolved" -UBOOT_VERSION="unresolved" -UBOOT_SRCREV="unresolved" +SOURCE_IDS="poky meta-arm meta-freescale meta-imx meta-openembedded meta-virtualization meta-clang meta-security" +LAYER_PATHS="sources/meta-clang sources/meta-imx/meta-imx-ml sources/meta-imx/meta-imx-bsp sources/meta-openembedded/meta-webserver sources/meta-openembedded/meta-gnome sources/meta-openembedded/meta-filesystems sources/meta-openembedded/meta-networking sources/meta-openembedded/meta-initramfs sources/meta-openembedded/meta-oe sources/meta-openembedded/meta-xfce sources/meta-openembedded/meta-python sources/meta-openembedded/meta-multimedia sources/meta-openembedded/meta-perl sources/meta-security/meta-parsec sources/meta-virtualization" +BBMASK_PATHS="meta-geisa-community/recipes-kernel/linux/linux-imx_6\.6\.bbappend meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite-host-tools_2\.16\.2\.bbappend" +GEISA_NXP_MACHINE_INCLUDE="conf/machine/imx93-11x11-lpddr4x-frdm.conf" +GEISA_MACHINE_INCLUDE="conf/machine/geisa-imx93-6.12.inc" +KERNEL_VERSION="6.12.34" +KERNEL_SRCREV="be78e49cb4339fd38c9a40019df49b72fbb8bcb7" +UBOOT_VERSION="2025.04" +UBOOT_SRCREV="44898b9f3cfe5ff881c11ab1c44b714041f2b4ac" +SOURCE_POKY="b642d6a4a93a23d5b99886844ff7b224aa7e13bf" +SOURCE_META_ARM="2de04c3d31e119d4bedbea24b9c63a8c113a1ce3" +SOURCE_META_FREESCALE="167ff4ddb79299cf5477e94620a9e598659c407b" +SOURCE_META_IMX="4d4651bec66c22aa91f1f8897140e77e20773ec4" +SOURCE_META_OPENEMBEDDED="dca497d728792e3cb655c78455c2d649af312ce8" +SOURCE_META_VIRTUALIZATION="898239e810acbb7db93299f20deec8afe434f11b" +SOURCE_META_CLANG="003cba92e982bdd565a6889f28799f8bba14957e" +SOURCE_META_SECURITY="784ca4b6584101e971b2d5d76ec7b716ad1301b5" diff --git a/platforms/nxp-imx93-yocto/releases/nxp-6.6.52-2.2.2.conf b/platforms/nxp-imx93-yocto/releases/nxp-6.6.52-2.2.2.conf index 7f0d6df..9e77e52 100644 --- a/platforms/nxp-imx93-yocto/releases/nxp-6.6.52-2.2.2.conf +++ b/platforms/nxp-imx93-yocto/releases/nxp-6.6.52-2.2.2.conf @@ -6,6 +6,11 @@ BUILD_DIR="build-development" MACHINE="geisa-imx93" DISTRO="geisa-dev" IMAGE="geisa-dev-image" +SOURCE_IDS="poky meta-arm meta-freescale meta-imx meta-imx-frdm meta-openembedded meta-virtualization" +LAYER_PATHS="sources/meta-imx/meta-imx-ml sources/meta-imx/meta-imx-bsp sources/meta-imx-frdm/meta-imx-bsp sources/meta-imx-frdm/meta-imx-sdk sources/meta-openembedded/meta-webserver sources/meta-openembedded/meta-gnome sources/meta-openembedded/meta-filesystems sources/meta-openembedded/meta-networking sources/meta-openembedded/meta-initramfs sources/meta-openembedded/meta-oe sources/meta-openembedded/meta-xfce sources/meta-openembedded/meta-python sources/meta-openembedded/meta-multimedia sources/meta-openembedded/meta-perl sources/meta-virtualization" +BBMASK_PATHS="meta-geisa-community/recipes-kernel/linux/linux-imx_6\.12\.bbappend meta-geisa-community/recipes-bsp/u-boot/u-boot-imx_2025\.04\.bbappend meta-geisa-community/recipes-core/systemd/systemd_257\.6\.bbappend meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite-host-tools_2\.19\.0\.bbappend meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite_2\.19\.0\.bbappend meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1\.0\.bbappend" +GEISA_NXP_MACHINE_INCLUDE="conf/machine/imx93frdm.conf" +GEISA_MACHINE_INCLUDE="conf/machine/geisa-imx93-6.6.inc" KERNEL_VERSION="6.6.52" KERNEL_SRCREV="5a0a5e71d2bd130577c7330cbb3764c68ebcb3dc" UBOOT_VERSION="2024.04" diff --git a/platforms/nxp-imx93-yocto/scripts/build.sh b/platforms/nxp-imx93-yocto/scripts/build.sh index d51c6c4..b10e76c 100755 --- a/platforms/nxp-imx93-yocto/scripts/build.sh +++ b/platforms/nxp-imx93-yocto/scripts/build.sh @@ -59,6 +59,35 @@ release_profile_check_sources --check build="$root/$BUILD_DIR" mkdir -p "$build/conf" sed "s|@PLATFORM_ROOT@|$root|g" "$root/build-configuration/templates/bblayers.conf" > "$build/conf/bblayers.conf" +layer_fragment="$build/conf/geisa-release-layers.conf" +: > "$layer_fragment" +printf '# Generated for %s (%s)\nBBLAYERS += " \\\n' "$RELEASE_ID" "$RELEASE_PROFILE_STATUS" >> "$layer_fragment" +declare -A layer_seen=() +for layer_path in $LAYER_PATHS; do + [ -z "${layer_seen[$layer_path]+x}" ] || { + echo "duplicate layer path for $RELEASE_ID: $layer_path" >&2 + exit 1 + } + layer_seen[$layer_path]=1 + [ -d "$root/$layer_path" ] || { + echo "missing layer path for $RELEASE_ID: $root/$layer_path" >&2 + exit 1 + } + printf ' %s/%s \\\n' "$root" "$layer_path" >> "$layer_fragment" +done +printf ' "\n' >> "$layer_fragment" +printf '\nBBMASK:append = " \\\n' >> "$layer_fragment" +declare -A mask_seen=() +for mask_path in $BBMASK_PATHS; do + [ -z "${mask_seen[$mask_path]+x}" ] || { + echo "duplicate BBMASK path for $RELEASE_ID: $mask_path" >&2 + exit 1 + } + mask_seen[$mask_path]=1 + printf ' %s \\\n' "$mask_path" >> "$layer_fragment" +done +printf ' "\n' >> "$layer_fragment" +printf '\ninclude conf/geisa-release-layers.conf\n' >> "$build/conf/bblayers.conf" cp "$root/build-configuration/templates/local.conf" "$build/conf/local.conf" state_file="$build/conf/geisa-source-state.conf" rm -f "$state_file" @@ -69,6 +98,8 @@ DL_DIR = "${DL_DIR:-$HOME/yocto-cache/downloads}" SSTATE_DIR = "${SSTATE_DIR:-$HOME/yocto-cache/sstate}" MACHINE = "$MACHINE" DISTRO = "$DISTRO" +GEISA_NXP_MACHINE_INCLUDE = "$GEISA_NXP_MACHINE_INCLUDE" +GEISA_MACHINE_INCLUDE = "$GEISA_MACHINE_INCLUDE" EOF set +u . "$root/sources/poky/oe-init-build-env" "$build" >/dev/null diff --git a/platforms/nxp-imx93-yocto/scripts/geisa-source-state.sh b/platforms/nxp-imx93-yocto/scripts/geisa-source-state.sh index a176260..b79ad7b 100755 --- a/platforms/nxp-imx93-yocto/scripts/geisa-source-state.sh +++ b/platforms/nxp-imx93-yocto/scripts/geisa-source-state.sh @@ -56,7 +56,7 @@ outer_status_filtered() { [ -n "$line" ] || continue path="${line:3}" case "$path" in - "${prefix}"sources/poky|"${prefix}"sources/meta-arm|"${prefix}"sources/meta-freescale|"${prefix}"sources/meta-imx|"${prefix}"sources/meta-imx-frdm|"${prefix}"sources/meta-openembedded|"${prefix}"sources/meta-virtualization) + "${prefix}"sources/poky|"${prefix}"sources/meta-arm|"${prefix}"sources/meta-freescale|"${prefix}"sources/meta-imx|"${prefix}"sources/meta-imx-frdm|"${prefix}"sources/meta-openembedded|"${prefix}"sources/meta-virtualization|"${prefix}"sources/meta-clang|"${prefix}"sources/meta-security) ;; *) printf '%s\n' "$line" ;; esac @@ -71,6 +71,8 @@ outer_excludes=( ":(exclude)${prefix}sources/meta-imx-frdm" ":(exclude)${prefix}sources/meta-openembedded" ":(exclude)${prefix}sources/meta-virtualization" + ":(exclude)${prefix}sources/meta-clang" + ":(exclude)${prefix}sources/meta-security" ) source_dirty=false diff --git a/platforms/nxp-imx93-yocto/scripts/release-profile.sh b/platforms/nxp-imx93-yocto/scripts/release-profile.sh index 17c28bf..6e4f025 100755 --- a/platforms/nxp-imx93-yocto/scripts/release-profile.sh +++ b/platforms/nxp-imx93-yocto/scripts/release-profile.sh @@ -10,7 +10,9 @@ set -euo pipefail GEISA_PLATFORM_ROOT="${GEISA_PLATFORM_ROOT:-$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)}" release_profile_error() { printf 'release profile error: %s\n' "$*" >&2; return 1; } -release_profile_source_ids=(poky meta-arm meta-freescale meta-imx meta-imx-frdm meta-openembedded meta-virtualization) +release_profile_known_source_ids=(poky meta-arm meta-freescale meta-imx meta-imx-frdm meta-openembedded meta-virtualization meta-clang meta-security) +release_profile_source_ids=() +release_profile_mask_paths=() release_profile_source_path() { case "$1" in poky) echo sources/poky;; meta-arm) echo sources/meta-arm;; @@ -18,6 +20,7 @@ release_profile_source_path() { meta-imx-frdm) echo sources/meta-imx-frdm;; meta-openembedded) echo sources/meta-openembedded;; meta-virtualization) echo sources/meta-virtualization;; + meta-clang) echo sources/meta-clang;; meta-security) echo sources/meta-security;; *) release_profile_error "unknown source id: $1";; esac } @@ -28,9 +31,63 @@ release_profile_source_var() { meta-imx-frdm) echo SOURCE_META_IMX_FRDM;; meta-openembedded) echo SOURCE_META_OPENEMBEDDED;; meta-virtualization) echo SOURCE_META_VIRTUALIZATION;; + meta-clang) echo SOURCE_META_CLANG;; meta-security) echo SOURCE_META_SECURITY;; *) release_profile_error "unknown source id: $1";; esac } +release_profile_validate_inventory() { + local source_id var value + local -A seen=() + release_profile_source_ids=() + [ -n "${SOURCE_IDS:-}" ] || { release_profile_error "SOURCE_IDS is empty"; return 1; } + for source_id in $SOURCE_IDS; do + [ -z "${seen[$source_id]+x}" ] || { + release_profile_error "duplicate source ID: $source_id"; return 1; + } + release_profile_source_path "$source_id" >/dev/null || return 1 + seen[$source_id]=1 + release_profile_source_ids+=("$source_id") + done + for source_id in "${release_profile_known_source_ids[@]}"; do + var="$(release_profile_source_var "$source_id")"; value="${!var:-}" + if [ -n "${seen[$source_id]+x}" ]; then + [[ "$value" =~ ^[0-9a-fA-F]{40}$ ]] || { + release_profile_error "$var must be a full commit for selected source $source_id"; return 1; + } + elif [ -n "$value" ]; then + release_profile_error "$var is set for unselected source $source_id"; return 1 + fi + done +} +release_profile_validate_layer_paths() { + local layer_path + local -A seen=() + [ -n "${LAYER_PATHS:-}" ] || { release_profile_error "LAYER_PATHS is empty"; return 1; } + for layer_path in $LAYER_PATHS; do + [ -z "${seen[$layer_path]+x}" ] || { + release_profile_error "duplicate layer path: $layer_path"; return 1; + } + seen[$layer_path]=1 + [[ "$layer_path" != /* && "$layer_path" != *..* ]] || { + release_profile_error "unsafe layer path: $layer_path"; return 1; + } + done +} +release_profile_validate_mask_paths() { + local mask_path + local -A seen=() + release_profile_mask_paths=() + for mask_path in ${BBMASK_PATHS:-}; do + [ -z "${seen[$mask_path]+x}" ] || { + release_profile_error "duplicate BBMASK path: $mask_path"; return 1; + } + [[ "$mask_path" =~ ^[A-Za-z0-9_./:+\\-]+$ && "$mask_path" != /* && "$mask_path" != *..* ]] || { + release_profile_error "unsafe BBMASK path: $mask_path"; return 1; + } + seen[$mask_path]=1 + release_profile_mask_paths+=("$mask_path") + done +} release_profile_default_id() { local line file="$GEISA_PLATFORM_ROOT/releases/default" [ -r "$file" ] || { release_profile_error "missing default release: $file"; return 1; } @@ -46,18 +103,33 @@ release_profile_default_id() { release_profile_load() { local file="$1" line key value [ -r "$file" ] || { release_profile_error "missing profile: $file"; return 1; } - unset RELEASE_ID STATUS NXP_BSP_VERSION YOCTO_SERIES BUILD_DIR MACHINE DISTRO IMAGE KERNEL_VERSION KERNEL_SRCREV UBOOT_VERSION UBOOT_SRCREV SOURCE_POKY SOURCE_META_ARM SOURCE_META_FREESCALE SOURCE_META_IMX SOURCE_META_IMX_FRDM SOURCE_META_OPENEMBEDDED SOURCE_META_VIRTUALIZATION + unset RELEASE_ID STATUS NXP_BSP_VERSION YOCTO_SERIES BUILD_DIR MACHINE DISTRO IMAGE KERNEL_VERSION KERNEL_SRCREV UBOOT_VERSION UBOOT_SRCREV SOURCE_IDS LAYER_PATHS BBMASK_PATHS GEISA_NXP_MACHINE_INCLUDE GEISA_MACHINE_INCLUDE SOURCE_POKY SOURCE_META_ARM SOURCE_META_FREESCALE SOURCE_META_IMX SOURCE_META_IMX_FRDM SOURCE_META_OPENEMBEDDED SOURCE_META_VIRTUALIZATION SOURCE_META_CLANG SOURCE_META_SECURITY while IFS= read -r line || [ -n "$line" ]; do [ -z "$line" ] || [[ "$line" == \#* ]] && continue [[ "$line" =~ ^([A-Z][A-Z0-9_]*)=\"([^\"]*)\"$ ]] || { release_profile_error "invalid profile line in $file: $line"; return 1; } key="${BASH_REMATCH[1]}"; value="${BASH_REMATCH[2]}" - [[ "$value" =~ ^[A-Za-z0-9._:/+-]+$ ]] || { - release_profile_error "unsafe value for $key in $file"; return 1; - } case "$key" in - RELEASE_ID|STATUS|NXP_BSP_VERSION|YOCTO_SERIES|BUILD_DIR|MACHINE|DISTRO|IMAGE|KERNEL_VERSION|KERNEL_SRCREV|UBOOT_VERSION|UBOOT_SRCREV|SOURCE_POKY|SOURCE_META_ARM|SOURCE_META_FREESCALE|SOURCE_META_IMX|SOURCE_META_IMX_FRDM|SOURCE_META_OPENEMBEDDED|SOURCE_META_VIRTUALIZATION) ;; + SOURCE_IDS|LAYER_PATHS) + [[ "$value" =~ ^[A-Za-z0-9._:/+\ -]+$ ]] || { + release_profile_error "unsafe value for $key in $file: $value"; return 1; + } + ;; + BBMASK_PATHS) + mask_value_re="^[-A-Za-z0-9._:/+\\ ]*$" + [[ "$value" =~ $mask_value_re ]] || { + release_profile_error "unsafe value for $key in $file: $value"; return 1; + } + ;; + *) + [[ "$value" =~ ^[A-Za-z0-9._:/+-]+$ ]] || { + release_profile_error "unsafe value for $key in $file"; return 1; + } + ;; + esac + case "$key" in + RELEASE_ID|STATUS|NXP_BSP_VERSION|YOCTO_SERIES|BUILD_DIR|MACHINE|DISTRO|IMAGE|KERNEL_VERSION|KERNEL_SRCREV|UBOOT_VERSION|UBOOT_SRCREV|SOURCE_IDS|LAYER_PATHS|BBMASK_PATHS|GEISA_NXP_MACHINE_INCLUDE|GEISA_MACHINE_INCLUDE|SOURCE_POKY|SOURCE_META_ARM|SOURCE_META_FREESCALE|SOURCE_META_IMX|SOURCE_META_IMX_FRDM|SOURCE_META_OPENEMBEDDED|SOURCE_META_VIRTUALIZATION|SOURCE_META_CLANG|SOURCE_META_SECURITY) ;; *) release_profile_error "unknown key $key in $file"; return 1;; esac printf -v "$key" '%s' "$value" @@ -67,6 +139,13 @@ release_profile_load() { for key in RELEASE_ID NXP_BSP_VERSION YOCTO_SERIES BUILD_DIR MACHINE DISTRO IMAGE; do [ -n "${!key:-}" ] || { release_profile_error "missing $key in $file"; return 1; } done + for key in SOURCE_IDS LAYER_PATHS GEISA_NXP_MACHINE_INCLUDE GEISA_MACHINE_INCLUDE; do + [ -n "${!key:-}" ] || { release_profile_error "missing $key in $file"; return 1; } + done + [ "${BBMASK_PATHS+x}" = x ] || { release_profile_error "missing BBMASK_PATHS in $file"; return 1; } + release_profile_validate_inventory + release_profile_validate_layer_paths + release_profile_validate_mask_paths # shellcheck disable=SC2034 RELEASE_PROFILE_FILE="$file" # shellcheck disable=SC2034 diff --git a/platforms/nxp-imx93-yocto/scripts/test-release-profiles.sh b/platforms/nxp-imx93-yocto/scripts/test-release-profiles.sh index 72fad3b..a026284 100755 --- a/platforms/nxp-imx93-yocto/scripts/test-release-profiles.sh +++ b/platforms/nxp-imx93-yocto/scripts/test-release-profiles.sh @@ -10,8 +10,11 @@ setup="$platform_root/scripts/setup-sources.sh" state="$platform_root/scripts/geisa-source-state.sh" export GEISA_PLATFORM_ROOT="$platform_root" . "$platform_root/scripts/release-profile.sh" -tmp_root="/home/swegener/work/gridops/tmp/release-profile-tests.$$" -mkdir -p "$tmp_root" +tmp_parent="${TMPDIR:-/tmp}" +tmp_root="$(mktemp -d "$tmp_parent/geisa-release-profile-tests.XXXXXX")" || { + echo "unable to create release-profile test temporary directory under $tmp_parent" >&2 + exit 1 +} trap 'rm -rf "$tmp_root"' EXIT assert_fails() { @@ -21,10 +24,50 @@ assert_fails() { fi } -grep -Fq 'nxp-6.6.52-2.2.2' <("$setup" --check) -grep -Fq 'nxp-6.6.52-2.2.2' <("$setup" --check --release nxp-6.6.52-2.2.2) +"$setup" --check >"$tmp_root/default-check" +grep -Fq 'nxp-6.6.52-2.2.2' "$tmp_root/default-check" +"$setup" --check --release nxp-6.6.52-2.2.2 >"$tmp_root/supported-check" +grep -Fq 'nxp-6.6.52-2.2.2' "$tmp_root/supported-check" assert_fails "$setup" --check --release no-such-release -assert_fails "$setup" --check --release nxp-6.12.34-2.1.0 + +if rg -n 'debug-tweaks' \ + "$platform_root/build-configuration/templates/local.conf" \ + "$platform_root/sources/meta-geisa-community"; then + echo "active GEISA platform metadata still uses debug-tweaks" >&2 + exit 1 +fi + +( + release_profile_select nxp-6.12.34-2.1.0 + release_profile_check_complete + [[ " ${SOURCE_IDS} " == *" meta-clang "* && " ${SOURCE_IDS} " == *" meta-security "* ]] +) +# shellcheck disable=SC2154,SC2034 +( + release_profile_select nxp-6.6.52-2.2.2 + [[ " ${SOURCE_IDS} " != *" meta-clang "* && " ${SOURCE_IDS} " != *" meta-security "* ]] +) +( + # shellcheck disable=SC2154 + release_profile_select nxp-6.6.52-2.2.2 + # shellcheck disable=SC2154 + [ "${#release_profile_mask_paths[@]}" -eq 6 ] + [ "${release_profile_mask_paths[0]}" = "meta-geisa-community/recipes-kernel/linux/linux-imx_6\\.12\\.bbappend" ] + [ "${release_profile_mask_paths[1]}" = "meta-geisa-community/recipes-bsp/u-boot/u-boot-imx_2025\\.04\\.bbappend" ] + [ "${release_profile_mask_paths[2]}" = "meta-geisa-community/recipes-core/systemd/systemd_257\\.6\\.bbappend" ] + [ "${release_profile_mask_paths[3]}" = "meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite-host-tools_2\\.19\\.0\\.bbappend" ] + [ "${release_profile_mask_paths[4]}" = "meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite_2\\.19\\.0\\.bbappend" ] + [ "${release_profile_mask_paths[5]}" = "meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1\\.0\\.bbappend" ] + BBMASK_PATHS="" + release_profile_validate_mask_paths + [ "${#release_profile_mask_paths[@]}" -eq 0 ] + # shellcheck disable=SC2034 + BBMASK_PATHS="duplicate duplicate" + assert_fails release_profile_validate_mask_paths + # shellcheck disable=SC2034 + BBMASK_PATHS="unsafe|mask" + assert_fails release_profile_validate_mask_paths +) mkdir -p "$tmp_root/releases" cp "$platform_root/releases/nxp-6.6.52-2.2.2.conf" "$tmp_root/releases/malformed.conf" @@ -39,13 +82,14 @@ fake="$tmp_root/fake" mkdir -p "$fake/releases" "$fake/sources" declare -A fake_revs # shellcheck disable=SC2154 -for source_id in "${release_profile_source_ids[@]}"; do +for source_id in "${release_profile_known_source_ids[@]}"; do path="$fake/$(case "$source_id" in poky) echo sources/poky;; meta-arm) echo sources/meta-arm;; meta-freescale) echo sources/meta-freescale;; meta-imx) echo sources/meta-imx;; meta-imx-frdm) echo sources/meta-imx-frdm;; meta-openembedded) echo sources/meta-openembedded;; - meta-virtualization) echo sources/meta-virtualization;; esac)" + meta-virtualization) echo sources/meta-virtualization;; + meta-clang) echo sources/meta-clang;; meta-security) echo sources/meta-security;; esac)" mkdir -p "$path" git -C "$path" init -q git -C "$path" config user.name test @@ -64,12 +108,17 @@ done printf '%s\n' 'MACHINE="fake"' printf '%s\n' 'DISTRO="fake"' printf '%s\n' 'IMAGE="fake"' + printf '%s\n' 'SOURCE_IDS="poky meta-arm meta-freescale meta-imx meta-imx-frdm meta-openembedded meta-virtualization"' + printf '%s\n' 'BBMASK_PATHS=""' + printf '%s\n' 'LAYER_PATHS="sources/meta-imx/meta-imx-ml"' + printf '%s\n' 'GEISA_NXP_MACHINE_INCLUDE="conf/machine/imx93frdm.conf"' + printf '%s\n' 'GEISA_MACHINE_INCLUDE="conf/machine/geisa-imx93-6.6.inc"' printf '%s\n' 'KERNEL_VERSION="6.6.52"' printf '%s\n' 'KERNEL_SRCREV="0123456789abcdef0123456789abcdef01234567"' printf '%s\n' 'UBOOT_VERSION="2024.04"' printf '%s\n' 'UBOOT_SRCREV="fedcba9876543210fedcba9876543210fedcba98"' # shellcheck disable=SC2154 - for source_id in "${release_profile_source_ids[@]}"; do + for source_id in poky meta-arm meta-freescale meta-imx meta-imx-frdm meta-openembedded meta-virtualization; do var="$(release_profile_source_var "$source_id")" printf '%s="%s"\n' "$var" "${fake_revs[$source_id]}" done @@ -97,7 +146,7 @@ done "$state" --release nxp-6.6.52-2.2.2 "$tmp_root/state-a" "$state" --release nxp-6.6.52-2.2.2 "$tmp_root/state-b" cmp "$tmp_root/state-a" "$tmp_root/state-b" -grep -Fqx 'GEISA_SOURCE_RELEASE = "nxp-6.6.52-2.2.2"' "$tmp_root/state-a" +grep -Fqx 'GEISA_RELEASE_ID = "nxp-6.6.52-2.2.2"' "$tmp_root/state-a" grep -Fqx 'GEISA_SOURCE_RELEASE_MATCH = "true"' "$tmp_root/state-a" grep -Fqx 'GEISA_EXPECTED_KERNEL_VERSION = "6.6.52"' "$tmp_root/state-a" grep -Fqx 'GEISA_EXPECTED_UBOOT_VERSION = "2024.04"' "$tmp_root/state-a" diff --git a/platforms/nxp-imx93-yocto/sources/meta-clang b/platforms/nxp-imx93-yocto/sources/meta-clang new file mode 160000 index 0000000..003cba9 --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-clang @@ -0,0 +1 @@ +Subproject commit 003cba92e982bdd565a6889f28799f8bba14957e diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/layer.conf b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/layer.conf index 9bbbc7b..201680f 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/layer.conf +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/layer.conf @@ -11,15 +11,4 @@ BBFILE_COLLECTIONS += "meta-geisa-community" BBFILE_PATTERN_meta-geisa-community= "^${LAYERDIR}/" BBFILE_PRIORITY_meta-geisa-community = "60" -LAYERSERIES_COMPAT_meta-geisa-community = "scarthgap" - -# Mask undefined recipes for imx93 machine -BBMASK:geisa-imx93-machine:append = " \ - meta-imx-frdm/meta-nxp-connectivity/recipes-matter/matter/matter.bbappend \ - meta-imx-frdm/meta-nxp-connectivity/recipes-openthread/packagegroups/packagegroup-nxp-openthread.bbappend \ - meta-imx-frdm/meta-nxp-connectivity/recipes-otbr/packagegroups/packagegroup-nxp-otbr.bbappend \ - meta-imx-frdm/meta-nxp-connectivity/recipes-zigbee-rcp/packagegroups/packagegroup-nxp-zigbee-rcp.bbappend \ - meta-imx-frdm/meta-imx-bsp/recipes-connectivity/nxp-wlan-sdk/nxp-wlan-sdk_git.bbappend \ -" - -PREFERRED_VERSION_firmware-ele-imx = "2.0.3.1" +LAYERSERIES_COMPAT_meta-geisa-community = "scarthgap walnascar" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93-6.12.inc b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93-6.12.inc new file mode 100644 index 0000000..6046f31 --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93-6.12.inc @@ -0,0 +1,7 @@ +# SPDX-License-Identifier: Apache-2.0 + +# The 6.12 NXP FRDM machine owns its board-support and M33 defaults. +MACHINE_FEATURES:append = " nxpwifi-all-sdio" +PREFERRED_VERSION_firmware-ele-imx = "2.0.3" +PREFERRED_VERSION_firmware-imx = "8.29" +GEISA_TFLITE_RUNTIME_VERSION = "2.19.0" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93-6.6.inc b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93-6.6.inc new file mode 100644 index 0000000..2cf1489 --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93-6.6.inc @@ -0,0 +1,20 @@ +# SPDX-License-Identifier: Apache-2.0 + +IMXBOOT_TARGETS:imx93-11x11-lpddr4x-frdm = "flash_singleboot" +BBMASK:append = " \ + meta-imx-frdm/meta-nxp-connectivity \ + meta-imx-frdm/meta-nxp-demo-experience \ + meta-imx-frdm/meta-nxp-connectivity/recipes-matter/matter/matter.bbappend \ + meta-imx-frdm/meta-nxp-connectivity/recipes-openthread/packagegroups/packagegroup-nxp-openthread.bbappend \ + meta-imx-frdm/meta-nxp-connectivity/recipes-otbr/packagegroups/packagegroup-nxp-otbr.bbappend \ + meta-imx-frdm/meta-nxp-connectivity/recipes-zigbee-rcp/packagegroups/packagegroup-nxp-zigbee-rcp.bbappend \ + meta-imx-frdm/meta-imx-bsp/recipes-connectivity/nxp-wlan-sdk/nxp-wlan-sdk_git.bbappend \ +" +PREFERRED_VERSION_firmware-ele-imx = "2.0.3.1" +GEISA_TFLITE_RUNTIME_VERSION = "2.16.2" +WKS_FILE_DEPENDS:remove:imx93-11x11-lpddr4x-frdm = "imx-m33-demos" +IMAGE_BOOT_FILES:remove:imx93-11x11-lpddr4x-frdm = " \ + imx93-11x11-evk_m33_TCM_power_mode_switch.bin \ + imx93-11x11-evk_m33_TCM_rpmsg_lite_pingpong_rtos_linux_remote.bin \ + imx93-11x11-evk_m33_TCM_rpmsg_lite_str_echo_rtos.bin \ +" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.conf b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.conf index db479b2..db7612b 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.conf +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.conf @@ -5,18 +5,10 @@ #@TYPE: Machine #@NAME: -#@DESCRIPTION: Machine configuration based on imx93frdm +#@DESCRIPTION: GEISA machine wrapper for the selected NXP FRDM release MACHINE = "geisa-imx93" -require conf/machine/imx93frdm.conf +require ${GEISA_NXP_MACHINE_INCLUDE} require conf/machine/geisa-imx93.inc - -IMXBOOT_TARGETS:imx93-11x11-lpddr4x-frdm = "flash_singleboot" +require ${GEISA_MACHINE_INCLUDE} PREFERRED_PROVIDER_virtual/kernel = "linux-imx" - -WKS_FILE_DEPENDS:remove:imx93-11x11-lpddr4x-frdm = "imx-m33-demos" -IMAGE_BOOT_FILES:remove:imx93-11x11-lpddr4x-frdm = " \ - imx93-11x11-evk_m33_TCM_power_mode_switch.bin \ - imx93-11x11-evk_m33_TCM_rpmsg_lite_pingpong_rtos_linux_remote.bin \ - imx93-11x11-evk_m33_TCM_rpmsg_lite_str_echo_rtos.bin \ -" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.inc b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.inc index bcbd6a4..a8b0ec7 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.inc +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/conf/machine/geisa-imx93.inc @@ -7,9 +7,4 @@ BBMULTICONFIG += "geisa-container" MACHINEOVERRIDES =. "geisa-imx93-machine:" -BBMASK:append = " \ - meta-imx-frdm/meta-nxp-connectivity \ - meta-imx-frdm/meta-nxp-demo-experience \ -" - WKS_FILE = "geisa-imx-partitioning.wks.in" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-bsp/u-boot/u-boot-imx_2025.04.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-bsp/u-boot/u-boot-imx_2025.04.bbappend new file mode 100644 index 0000000..c5f44d6 --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-bsp/u-boot/u-boot-imx_2025.04.bbappend @@ -0,0 +1,3 @@ +# SPDX-License-Identifier: Apache-2.0 + +SRCREV:geisa-imx93-machine = "44898b9f3cfe5ff881c11ab1c44b714041f2b4ac" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-connectivity/bluez5/bluez5_%.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-connectivity/bluez5/bluez5_%.bbappend index 62e30c2..725387d 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-connectivity/bluez5/bluez5_%.bbappend +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-connectivity/bluez5/bluez5_%.bbappend @@ -4,7 +4,7 @@ FILESEXTRAPATHS:prepend := "${THISDIR}/files:" SRC_URI += "file://geisa-bluetooth.conf" do_install:append() { - install -D -m 0644 ${WORKDIR}/geisa-bluetooth.conf \ + install -D -m 0644 ${UNPACKDIR}/geisa-bluetooth.conf \ ${D}${systemd_system_unitdir}/bluetooth.service.d/geisa.conf } diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/files/README.md b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/files/README.md index e8e35f5..aba6392 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/files/README.md +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/files/README.md @@ -186,29 +186,29 @@ a tag; to reproduce that release, check out its tag before building. Use ## Release Profiles -The default release is `nxp-6.6.52-2.2.2`. +The default supported release is `nxp-6.6.52-2.2.2`. -Use the existing build command for the default release: +The experimental `nxp-6.12.34-2.1.0` release uses Walnascar / Yocto 5.2 and +the FRDM-i.MX93 machine provided by the main NXP `meta-imx` release. It also +uses `meta-clang` and `meta-security/meta-parsec`. The older +`meta-imx-frdm` layer is used only by the 6.6 release. -``` -ACCEPT_FSL_EULA=1 ./scripts/build.sh development -``` +Select a release with `--release`: -To select it explicitly: +```sh +ACCEPT_FSL_EULA=1 ./scripts/build.sh development \ + --release nxp-6.6.52-2.2.2 -- bitbake geisa-dev-image -``` -./scripts/setup-sources.sh --release nxp-6.6.52-2.2.2 ACCEPT_FSL_EULA=1 ./scripts/build.sh development \ - --release nxp-6.6.52-2.2.2 -``` + --release nxp-6.12.34-2.1.0 -- bitbake geisa-dev-image -The `nxp-6.12.34-2.1.0` profile is reserved for the newer NXP BSP. Its source -revisions and release-specific recipe changes have not yet been added, so it -cannot currently be selected for setup or build. +### Experimental 6.12 status -Source setup verifies the selected release against the checked-out submodule -revisions. It stops if a submodule contains local changes or does not match the -selected profile. +The 6.12 image builds with Linux 6.12.34 and U-Boot 2025.04. Walnascar support +includes unpack-path compatibility, explicit development image features, +TensorFlow Lite 2.19, and read-only application-container handling. Removable- +media validation is still required. Keep the known-good 6.6 eMMC image until it +passes. ## NXP License Acceptance @@ -237,17 +237,30 @@ build: ACCEPT_FSL_EULA=1 ./scripts/build.sh development -- bitbake -p -Deployment artifacts are written under: +Deployment artifacts are written under the selected release's build directory: + + /tmp/deploy/images/geisa-imx93/ + +For example: build-development/tmp/deploy/images/geisa-imx93/ + build-development-nxp-6.12.34-2.1.0/tmp/deploy/images/geisa-imx93/ The compressed disk image is named similarly to: geisa-dev-image-geisa-imx93.rootfs-.wic.zst -The deployment directory also contains the kernel, device tree, -installed-package manifest, license information, SPDX output, and related build -artifacts. +The deployment directory also contains the `.wic.bmap`, package manifest, +testdata JSON, image-manifest JSON, kernel, device trees, license information, +and SPDX output. + +The testdata JSON records the selected release, the GEISA Community repository +revision and dirty state, the expected and actual source revisions, and the +expected kernel and U-Boot revisions. `GEISA_SOURCE_REVISION` identifies the +GEISA Community repository revision, not an NXP layer revision. + +An image built with uncommitted repository changes records a dirty source state +and should be used for development validation rather than publication. For general sanity, you should calculate the WIC SHA-256 before writing the image: @@ -582,6 +595,15 @@ warning-log details. The script tolerates missing optional tools and reports the information available on the currently running image. +The output summarizes systemd state, LXC containers, network interfaces, and +available thermal readings. Missing optional tools and command failures are +reported rather than silently omitted. + +Set `GEISA_LXC_LS_PATH` to use a specific `lxc-ls` executable. + +The output is intended for simple status checks and quick diagnostics, including +use on smaller displays such as a 10-inch Raspberry Pi display. + Usage: geisa-system-state [--once] [--debug] diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/geisa-image-documentation.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/geisa-image-documentation.bb index 44891ee..fce4940 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/geisa-image-documentation.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-image-documentation/geisa-image-documentation.bb @@ -5,14 +5,14 @@ DESCRIPTION = "Installs the canonical community-image documentation and license LICENSE = "Apache-2.0" LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10" SRC_URI = "file://README.md file://NOTICE.md file://Apache-2.0.txt" -S = "${WORKDIR}" +S = "${UNPACKDIR}" inherit allarch do_install() { install -d -m 0755 ${D}${datadir}/doc/geisa-image/LICENSES - install -m 0644 ${WORKDIR}/README.md ${D}${datadir}/doc/geisa-image/README.md - install -m 0644 ${WORKDIR}/NOTICE.md ${D}${datadir}/doc/geisa-image/NOTICE.md - install -m 0644 ${WORKDIR}/Apache-2.0.txt ${D}${datadir}/doc/geisa-image/LICENSES/Apache-2.0.txt + install -m 0644 ${UNPACKDIR}/README.md ${D}${datadir}/doc/geisa-image/README.md + install -m 0644 ${UNPACKDIR}/NOTICE.md ${D}${datadir}/doc/geisa-image/NOTICE.md + install -m 0644 ${UNPACKDIR}/Apache-2.0.txt ${D}${datadir}/doc/geisa-image/LICENSES/Apache-2.0.txt } # Keep the published image documentation in the installable main package. diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-sudo-policy/geisa-sudo-policy.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-sudo-policy/geisa-sudo-policy.bb index 83580f1..acff9e1 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-sudo-policy/geisa-sudo-policy.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa-sudo-policy/geisa-sudo-policy.bb @@ -9,13 +9,13 @@ LICENSE = "Apache-2.0" LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10" SRC_URI = "file://10-sudo-group" -S = "${WORKDIR}" +S = "${UNPACKDIR}" RDEPENDS:${PN} = "sudo" do_install() { install -d -m 0750 ${D}${sysconfdir}/sudoers.d - install -m 0440 ${WORKDIR}/10-sudo-group ${D}${sysconfdir}/sudoers.d/10-sudo-group + install -m 0440 ${UNPACKDIR}/10-sudo-group ${D}${sysconfdir}/sudoers.d/10-sudo-group } FILES:${PN} = "${sysconfdir}/sudoers.d/10-sudo-group" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/files/assemble-nxp-ethosu-tflite-profile.py b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/files/assemble-nxp-ethosu-tflite-profile.py index 6042d5f..714bcfd 100755 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/files/assemble-nxp-ethosu-tflite-profile.py +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/files/assemble-nxp-ethosu-tflite-profile.py @@ -13,7 +13,6 @@ PROFILE = "nxp-ethosu-tflite" PROFILE_VERSION = "2" -PYTHON_SITE = Path("usr/lib/python3.12/site-packages") PYAV_WHEEL = "av-18.0.0-cp311-abi3-manylinux_2_28_aarch64.whl" PYAV_SHA256 = "4d683b7747a0ba9222b8a5f81e41db5f796e7f64473454ec4fe2548e083c2fa0" PYAV_TAG = "cp311-abi3-manylinux_2_28_aarch64" @@ -25,14 +24,8 @@ NATIVE_SOURCES = { "lib/libethosu_delegate.so": "usr/lib/libethosu_delegate.so", - "lib/libtensorflow-lite.so.2.16.2": "usr/lib/libtensorflow-lite.so.2.16.2", "lib/libethosu.so.1.0.0": "usr/lib/libethosu.so.1.0.0", } -LINKS = { - "lib/libethosu.so": "libethosu.so.1.0.0", - "lib/libethosu.so.1": "libethosu.so.1.0.0", - "lib/libtensorflow-lite.so": "libtensorflow-lite.so.2.16.2", -} NUMPY_EXCLUDES = { "_pyinstaller", "distutils", @@ -69,6 +62,29 @@ def sha256(path: Path) -> str: return digest.hexdigest() +def tensorflow_lite_library(sysroot: Path) -> tuple[str, str]: + libraries = sorted( + path + for path in (sysroot / "usr/lib").glob("libtensorflow-lite.so.*") + if path.is_file() + ) + if len(libraries) != 1: + raise ValueError(f"expected one TensorFlow Lite runtime library, found: {libraries}") + name = libraries[0].name + return name, f"usr/lib/{name}" + + +def python_site(sysroot: Path) -> Path: + sites = sorted( + path + for path in (sysroot / "usr/lib").glob("python*/site-packages") + if path.is_dir() and (path / "tflite_runtime").is_dir() + ) + if len(sites) != 1: + raise ValueError(f"expected one Python runtime site-packages tree, found: {sites}") + return sites[0].relative_to(sysroot) + + def ensure_safe_relative(name: str) -> Path: path = Path(name) if not name or path.is_absolute() or ".." in path.parts: @@ -189,14 +205,25 @@ def assemble(sysroot: Path, wheel: Path, output: Path, source_revision: str) -> if output.exists(): raise ValueError(f"refusing to replace profile output: {output}") output.mkdir(parents=True) - for destination, source in NATIVE_SOURCES.items(): + tensorflow_library, tensorflow_source = tensorflow_lite_library(sysroot) + native_sources = { + **NATIVE_SOURCES, + f"lib/{tensorflow_library}": tensorflow_source, + } + links = { + "lib/libethosu.so": "libethosu.so.1.0.0", + "lib/libethosu.so.1": "libethosu.so.1.0.0", + "lib/libtensorflow-lite.so": tensorflow_library, + } + site = python_site(sysroot) + for destination, source in native_sources.items(): candidate = sysroot / source if not candidate.is_file(): raise ValueError(f"missing declared Yocto runtime input: {candidate}") copy_file(candidate, output / destination) - copy_tree(sysroot / PYTHON_SITE / "tflite_runtime", output / "python" / "tflite_runtime", {"test", "tests", "__pycache__"}) - copy_tree(sysroot / PYTHON_SITE / "numpy", output / "python" / "numpy", NUMPY_EXCLUDES) - for destination, target in LINKS.items(): + copy_tree(sysroot / site / "tflite_runtime", output / "python" / "tflite_runtime", {"test", "tests", "__pycache__"}) + copy_tree(sysroot / site / "numpy", output / "python" / "numpy", NUMPY_EXCLUDES) + for destination, target in links.items(): link = output / destination link.parent.mkdir(parents=True, exist_ok=True) link.symlink_to(target) diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-nxp-ethosu-tflite-profile.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-nxp-ethosu-tflite-profile.bb index 8e3a9db..9bd83af 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-nxp-ethosu-tflite-profile.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-nxp-ethosu-tflite-profile.bb @@ -18,7 +18,7 @@ SRC_URI = " \ " SRC_URI[pyav.sha256sum] = "${PYAV_SHA256}" -S = "${WORKDIR}" +S = "${UNPACKDIR}" include ${TOPDIR}/conf/geisa-source-state.conf PACKAGE_ARCH = "${MACHINE_ARCH}" @@ -33,12 +33,12 @@ RDEPENDS:${PN} += "geisa-runtime-groups" do_install() { output="${D}/platform/profiles/nxp-ethosu-tflite" rm -rf "$output" - python3 "${WORKDIR}/assemble-nxp-ethosu-tflite-profile.py" assemble \ + python3 "${UNPACKDIR}/assemble-nxp-ethosu-tflite-profile.py" assemble \ --sysroot "${RECIPE_SYSROOT}" \ --wheel "${DL_DIR}/${PYAV_WHEEL}" \ --root "$output" \ --source-revision "${GEISA_SOURCE_REVISION}" - python3 "${WORKDIR}/assemble-nxp-ethosu-tflite-profile.py" verify --root "$output" + python3 "${UNPACKDIR}/assemble-nxp-ethosu-tflite-profile.py" verify --root "$output" chown -R 0:0 "$output" chmod -R go-w "$output" } @@ -46,7 +46,7 @@ do_install() { FILES:${PN} = "/platform/profiles/nxp-ethosu-tflite" # These libraries are deliberately private to the read-only profile; managed # applications load them through the profile's explicit library path. -PRIVATE_LIBS:${PN} = "libethosu.so.1.0.0 libethosu_delegate.so libtensorflow-lite.so.2.16.2" +PRIVATE_LIBS:${PN} = "libethosu.so.1.0.0 libethosu_delegate.so libtensorflow-lite.so.${GEISA_TFLITE_RUNTIME_VERSION}" INSANE_SKIP:${PN} += "already-stripped dev-so file-rdeps ldflags" SKIP_FILEDEPS:${PN} = "1" do_install[vardeps] += "PYAV_SHA256 PYAV_URL GEISA_SOURCE_REVISION" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-runtime-defaults.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-runtime-defaults.bb index 28f1214..745c49a 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-runtime-defaults.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/geisa/geisa-runtime-defaults.bb @@ -7,13 +7,13 @@ LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7ca SRC_URI = "file://geisa" -S = "${WORKDIR}" +S = "${UNPACKDIR}" inherit allarch do_install() { install -d ${D}${sysconfdir}/default - install -m 0644 ${WORKDIR}/geisa ${D}${sysconfdir}/default/geisa + install -m 0644 ${UNPACKDIR}/geisa ${D}${sysconfdir}/default/geisa } FILES:${PN} = "${sysconfdir}/default/geisa" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/systemd/systemd_%.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/systemd/systemd_%.bbappend index 208d60a..52579b9 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/systemd/systemd_%.bbappend +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/systemd/systemd_%.bbappend @@ -14,11 +14,11 @@ do_install:append() { fi install -d ${D}/${systemd_system_unitdir}/systemd-networkd-wait-online.service.d - install -m 0644 ${WORKDIR}/geisa-networkd-wait-online.conf \ + install -m 0644 ${UNPACKDIR}/geisa-networkd-wait-online.conf \ ${D}/${systemd_system_unitdir}/systemd-networkd-wait-online.service.d/geisa-networkd-wait-online.conf install -d ${D}/${sysconfdir}/systemd/network - install -m 0644 ${WORKDIR}/10-geisa-end0.link \ + install -m 0644 ${UNPACKDIR}/10-geisa-end0.link \ ${D}/${sysconfdir}/systemd/network/10-geisa-end0.link } diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/systemd/systemd_257.6.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/systemd/systemd_257.6.bbappend new file mode 100644 index 0000000..df249c6 --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/systemd/systemd_257.6.bbappend @@ -0,0 +1 @@ +PACKAGECONFIG:remove:geisa-container = "sysvinit" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/udev/geisa-ethosu-device-permissions.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/udev/geisa-ethosu-device-permissions.bb index 41abda8..408583d 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/udev/geisa-ethosu-device-permissions.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-core/udev/geisa-ethosu-device-permissions.bb @@ -10,7 +10,7 @@ LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7ca SRC_URI = "file://99-geisa-ethosu.rules" -S = "${WORKDIR}" +S = "${UNPACKDIR}" inherit allarch useradd @@ -20,7 +20,7 @@ GROUPMEMS_PARAM:${PN} = "--group ethosu --add geisa" do_install() { install -d ${D}${nonarch_base_libdir}/udev/rules.d - install -m 0644 ${WORKDIR}/99-geisa-ethosu.rules \ + install -m 0644 ${UNPACKDIR}/99-geisa-ethosu.rules \ ${D}${nonarch_base_libdir}/udev/rules.d/99-geisa-ethosu.rules } diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-image/images/geisa-dev-image.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-image/images/geisa-dev-image.bb index b1efcda..f47b76d 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-image/images/geisa-dev-image.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-image/images/geisa-dev-image.bb @@ -6,7 +6,7 @@ require geisa-common.inc # Developer tools are collected in packagegroup-geisa-dev-tools. # System tools -IMAGE_FEATURES += "allow-empty-password debug-tweaks empty-root-password \ +IMAGE_FEATURES += "allow-empty-password empty-root-password \ post-install-logging" # Clear REPRODUCIBLE_TIMESTAMP_ROOTFS variable to get the build time in /etc/version @@ -34,6 +34,7 @@ GEISA_DEV_RUNTIME_INSTALL = " \ geisa-sudo-policy \ mosquitto-clients \ nodejs \ + systemd-analyze \ " # The FRDM-i.MX93 uses the NXP IW612 SDIO/UART module. This exact package is diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-kernel/linux/linux-imx/nxp-6.12.cfg b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-kernel/linux/linux-imx/nxp-6.12.cfg new file mode 100644 index 0000000..06823bc --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-kernel/linux/linux-imx/nxp-6.12.cfg @@ -0,0 +1,6 @@ +# SPDX-License-Identifier: Apache-2.0 +# +# The pinned NXP 6.12 Cadence Kconfig allows DRM_CDNS_HDMI to call the CEC +# helpers without selecting the object that implements them. Keep the HDMI +# path enabled and build its CEC companion into the kernel. +CONFIG_DRM_CDNS_HDMI_CEC=y diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-kernel/linux/linux-imx_6.12.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-kernel/linux/linux-imx_6.12.bbappend new file mode 100644 index 0000000..da5b2cf --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-kernel/linux/linux-imx_6.12.bbappend @@ -0,0 +1,27 @@ +# SPDX-License-Identifier: Apache-2.0 + +FILESEXTRAPATHS:prepend := "${THISDIR}/${PN}:" + +SRCREV:geisa-imx93-machine = "be78e49cb4339fd38c9a40019df49b72fbb8bcb7" +LINUX_VERSION:geisa-imx93-machine = "6.12.34" + +SRC_URI:append = " \ + file://container.cfg \ + file://development.cfg \ + file://nxp-6.12.cfg \ + file://unused-configs.cfg \ +" + +DELTA_KERNEL_DEFCONFIG:geisa-imx93-machine = "container.cfg development.cfg nxp-6.12.cfg unused-configs.cfg" + +DEPENDS:append:geisa-imx93-machine = " wireless-regdb" +SYSROOT_DIRS:append:geisa-imx93-machine = " ${nonarch_base_libdir}/firmware" + +do_configure:prepend:geisa-imx93-machine() { + for firmware in regulatory.db regulatory.db.p7s; do + source="${RECIPE_SYSROOT}${nonarch_base_libdir}/firmware/${firmware}" + test -r "$source" || \ + bbfatal "wireless-regdb did not stage required firmware: $source" + install -D -m 0644 "$source" "${S}/firmware/${firmware}" + done +} diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite-host-tools_2.19.0.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite-host-tools_2.19.0.bbappend new file mode 100644 index 0000000..19107c9 --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite-host-tools_2.19.0.bbappend @@ -0,0 +1,14 @@ +# SPDX-License-Identifier: Apache-2.0 + +# protobuf.cmake derives the native-tools module path from this TensorFlow +# Lite source root when the native_tools subdirectory is configured directly. +DEPENDS:append:class-target = " flatbuffers-native" +EXTRA_OECMAKE:append:class-target = " \ + -DFLATC_INSTALL_PREFIX=${B}/flatbuffers-flatc-install \ + -DTFLITE_SOURCE_DIR=${S}/tensorflow/lite \ + -DTFLITE_HOST_TOOLS_DIR=${STAGING_BINDIR_NATIVE} \ + -DTFLITE_NATIVE_TOOLS_BUILD_PROTOC=OFF \ +" +EXTRA_OECMAKE:append:class-native = " \ + -DTFLITE_NATIVE_TOOLS_BUILD_PROTOC=ON \ +" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite_2.19.0.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite_2.19.0.bbappend new file mode 100644 index 0000000..1f7f0e7 --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-libraries/tensorflow-lite/tensorflow-lite_2.19.0.bbappend @@ -0,0 +1,6 @@ +# SPDX-License-Identifier: Apache-2.0 + +# native_utils.cmake appends /bin to this value when locating protoc. The +# NXP recipe passes STAGING_BINDIR_NATIVE, which produces an invalid /bin/bin +# path for the 2.19 cross-compile. +EXTRA_OECMAKE:append = " -DTFLITE_HOST_TOOLS_DIR=${STAGING_DIR_NATIVE}/usr" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/README b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/README index e9d7615..c4426ab 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/README +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/README @@ -9,8 +9,8 @@ Website: https://www.pragsolconsulting.com/ `geisa-ethosu-smoke-test` is a host-side development diagnostic. It is not a GEISA application, a managed application, or a performance benchmark. -The helper uses the Apache-2.0 TensorFlow Lite 2.16.2 MobileNet example and -Grace Hopper image already installed by the `tensorflow-lite` package. It +The helper uses the Apache-2.0 TensorFlow Lite MobileNet example and Grace +Hopper image installed by the release-selected `tensorflow-lite` package. It checks the source model SHA-256, uses Vela for `ethos-u65-256` to create a temporary compiled model, loads `/usr/lib/libethosu_delegate.so`, and runs one inference through `/dev/ethosu0`. It succeeds only when the delegate reports diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/geisa-ethosu-smoke-test b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/geisa-ethosu-smoke-test index a35c5f3..20fff5b 100755 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/geisa-ethosu-smoke-test +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/files/geisa-ethosu-smoke-test @@ -31,8 +31,9 @@ while [ "$#" -gt 0 ]; do esac done -model="${GEISA_ETHOSU_SMOKE_MODEL:-/usr/bin/tensorflow-lite-2.16.2/examples/mobilenet_v1_1.0_224_quant.tflite}" -input="${GEISA_ETHOSU_SMOKE_INPUT:-/usr/bin/tensorflow-lite-2.16.2/examples/grace_hopper.bmp}" +tflite_examples="/usr/bin/tensorflow-lite-@GEISA_TFLITE_RUNTIME_VERSION@/examples" +model="${GEISA_ETHOSU_SMOKE_MODEL:-${tflite_examples}/mobilenet_v1_1.0_224_quant.tflite}" +input="${GEISA_ETHOSU_SMOKE_INPUT:-${tflite_examples}/grace_hopper.bmp}" delegate="${GEISA_ETHOSU_SMOKE_DELEGATE:-/usr/lib/libethosu_delegate.so}" device="${GEISA_ETHOSU_SMOKE_DEVICE:-/dev/ethosu0}" vela="${GEISA_ETHOSU_SMOKE_VELA:-/usr/bin/vela}" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1.0.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1.0.bb index 3943b20..37f6c68 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1.0.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1.0.bb @@ -31,10 +31,12 @@ RDEPENDS:${PN} = " \ do_install() { install -d ${D}${bindir} - install -m 0755 ${WORKDIR}/geisa-ethosu-smoke-test \ + install -m 0755 ${S}/geisa-ethosu-smoke-test \ + ${D}${bindir}/geisa-ethosu-smoke-test + sed -i -e 's/@GEISA_TFLITE_RUNTIME_VERSION@/${GEISA_TFLITE_RUNTIME_VERSION}/g' \ ${D}${bindir}/geisa-ethosu-smoke-test install -d ${D}${datadir}/geisa/examples/ethosu-smoke - install -m 0644 ${WORKDIR}/README \ + install -m 0644 ${S}/README \ ${D}${datadir}/geisa/examples/ethosu-smoke/README } diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1.0.bbappend b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1.0.bbappend new file mode 100644 index 0000000..9a0c64f --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-ethosu-smoke-test/geisa-ethosu-smoke-test_1.0.bbappend @@ -0,0 +1,3 @@ +# SPDX-License-Identifier: Apache-2.0 + +S = "${UNPACKDIR}" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-platform-mount/geisa-platform-mount_1.0.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-platform-mount/geisa-platform-mount_1.0.bb index 42bd1fc..340c1a9 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-platform-mount/geisa-platform-mount_1.0.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-platform-mount/geisa-platform-mount_1.0.bb @@ -6,7 +6,7 @@ LICENSE = "Apache-2.0" LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7cacdbeed46a0096b10" SRC_URI = "file://geisa-platform-generator" -S = "${WORKDIR}" +S = "${UNPACKDIR}" inherit allarch @@ -14,7 +14,7 @@ RDEPENDS:${PN} = "util-linux" do_install() { install -d -m 0755 ${D}${nonarch_libdir}/systemd/system-generators - install -m 0755 ${WORKDIR}/geisa-platform-generator \ + install -m 0755 ${UNPACKDIR}/geisa-platform-generator \ ${D}${nonarch_libdir}/systemd/system-generators/geisa-platform-generator } diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/files/geisa-system-state b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/files/geisa-system-state index 2dc5f50..84d7aff 100755 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/files/geisa-system-state +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/files/geisa-system-state @@ -18,6 +18,7 @@ DEBUG=0 SYSFS_ROOT="${SYSFS_ROOT:-/sys}" PROC_ROOT="${PROC_ROOT:-/proc}" GEISA_STATE_ROOT="${GEISA_STATE_ROOT:-/var/lib/geisa}" +GEISA_LXC_LS_PATH="${GEISA_LXC_LS_PATH:-}" usage() { cat <<'EOF' @@ -105,7 +106,7 @@ print_network() { while IFS='|' read -r name state; do [ -n "$name" ] || continue address="$(printf '%s\n' "$rows" | awk -v interface="$name" '$1 == interface { print $2; exit }')" - [ -z "$summary" ] || summary="$summary; " + [ -z "$summary" ] || summary="$summary " summary="${summary}${name} ${state:-UNKNOWN} ${address:-}" done </dev/null || printf 1)" = 0 ]; then + output="$($lxc_ls --fancy -F NAME,STATE,AUTOSTART,GROUPS,IPV4,UNPRIVILEGED 2>/dev/null)" + lxc_rc=$? + elif have sudo && sudo -n true >/dev/null 2>&1; then + output="$(sudo -n "$lxc_ls" --fancy -F NAME,STATE,AUTOSTART,GROUPS,IPV4,UNPRIVILEGED 2>/dev/null)" + lxc_rc=$? + else + output="$($lxc_ls --fancy -F NAME,STATE,AUTOSTART,GROUPS,IPV4,UNPRIVILEGED 2>/dev/null)" + lxc_rc=$? + fi + if [ "$lxc_rc" -ne 0 ]; then + printf 'lxc inventory unavailable (permission denied or command failed)\n' return fi - output="$(lxc-ls --fancy 2>/dev/null || true)" # lxc-ls prints its column heading even when there are no containers. rows="$(printf '%s\n' "$output" | sed -n '2,$p' | sed '/^[[:space:]]*$/d')" if [ -n "$output" ] && [ -n "$rows" ]; then @@ -246,9 +278,9 @@ print_report() { print_geisa_identity print_network print_thermal - print_lxc print_managed_apps print_systemd + print_lxc print_filesystems print_resources print_debug diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/geisa-system-state_1.0.bb b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/geisa-system-state_1.0.bb index e9ad941..9787527 100644 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/geisa-system-state_1.0.bb +++ b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/geisa-system-state_1.0.bb @@ -11,13 +11,13 @@ LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/Apache-2.0;md5=89aea4e17d99a7ca SRC_URI = "file://geisa-system-state" -S = "${WORKDIR}" +S = "${UNPACKDIR}" inherit allarch do_install() { install -d ${D}${bindir} - install -m 0755 ${WORKDIR}/geisa-system-state ${D}${bindir}/geisa-system-state + install -m 0755 ${UNPACKDIR}/geisa-system-state ${D}${bindir}/geisa-system-state } FILES:${PN} = "${bindir}/geisa-system-state" diff --git a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/tests/test-geisa-system-state.sh b/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/tests/test-geisa-system-state.sh deleted file mode 100755 index 18cd402..0000000 --- a/platforms/nxp-imx93-yocto/sources/meta-geisa-community/recipes-support/geisa-system-state/tests/test-geisa-system-state.sh +++ /dev/null @@ -1,158 +0,0 @@ -#!/bin/sh -# Fixture test for the human-readable GEISA system-state report. -set -eu - -script=${1:?usage: test-geisa-system-state.sh /path/to/geisa-system-state} -work=$(mktemp -d) -trap 'rm -rf "$work"' EXIT INT TERM -fake="$work/bin" -mkdir -p "$fake" "$work/sys/fs/cgroup" "$work/sys/class/thermal/thermal_zone0" \ - "$work/proc" "$work/state/app-registry" - -cat >"$work/sys/fs/cgroup/cgroup.controllers" <<'EOF' -cpuset cpu io memory pids -EOF -printf 'cpu-thermal\n' >"$work/sys/class/thermal/thermal_zone0/type" -printf '63400\n' >"$work/sys/class/thermal/thermal_zone0/temp" -cat >"$work/proc/meminfo" <<'EOF' -MemTotal: 1880000 kB -MemAvailable: 1006000 kB -SwapTotal: 0 kB -SwapFree: 0 kB -EOF -cat >"$work/state/app-registry/managed-apps.json" <<'EOF' -{"app_instances":[{"app_id":"com.example.alpha","display_name":"Alpha","install_state":"installed","execution_state":"running"}]} -EOF - -make_tool() { - cat >"$fake/$1" - chmod +x "$fake/$1" -} - -make_tool date <<'EOF' -#!/bin/sh -printf '2026-07-29 12:23:43 UTC\n' -EOF -make_tool hostname <<'EOF' -#!/bin/sh -printf 'geisa-imx93\n' -EOF -make_tool id <<'EOF' -#!/bin/sh -[ "$1" = geisa ] && { printf 'uid=999(geisa) gid=999(geisa) groups=999(geisa),995(ethosu)\n'; exit 0; } -exit 1 -EOF -make_tool stat <<'EOF' -#!/bin/sh -printf 'cgroup2fs\n' -EOF -make_tool ip <<'EOF' -#!/bin/sh -case "$*" in - '-o -4 addr show') printf '2: end0 inet 192.0.2.188/24 brd 192.0.2.255 scope global end0\n' ;; - '-o link show') printf '1: lo: mtu 65536 state UNKNOWN mode DEFAULT\n2: end0: mtu 1500 state UP mode DEFAULT\n3: lxcbr0: mtu 1500 state DOWN mode DEFAULT\n' ;; - *) : ;; -esac -EOF -make_tool df <<'EOF' -#!/bin/sh -printf '%s\n' 'Filesystem Size Used Avail Use% Mounted on' '/dev/mmcblk0p2 7.7G 1.3G 6.0G 18% /' '/dev/mmcblk0p3 5.8G 225M 5.2G 5% /platform' -EOF -make_tool uptime <<'EOF' -#!/bin/sh -printf ' 12:23:44 up 1:36, 0 user, load average: 2.18, 1.16, 0.61\n' -EOF -make_tool free <<'EOF' -#!/bin/sh -printf '%s\n' ' total used free shared buff/cache available' 'Mem: 1880 874 250 25 870 1006' 'Swap: 0 0 0' -EOF -make_tool lxc-ls <<'EOF' -#!/bin/sh -printf '%s\n' 'NAME STATE AUTOSTART GROUPS IPV4 IPV6 UNPRIVILEGED' 'geisa-app-alpha RUNNING 0 - 10.0.3.6 - false' -EOF -make_tool systemctl <<'EOF' -#!/bin/sh -exit 0 -EOF -make_tool clear <<'EOF' -#!/bin/sh -printf clear-called >&2 -EOF -make_tool journalctl <<'EOF' -#!/bin/sh -exit 0 -EOF -make_tool ss <<'EOF' -#!/bin/sh -exit 0 -EOF - -output="$work/once.out" -PATH="$fake:$PATH" SYSFS_ROOT="$work/sys" PROC_ROOT="$work/proc" GEISA_STATE_ROOT="$work/state" \ - "$script" --once >"$output" - -assert() { grep -Fqx "$1" "$output" >/dev/null || { printf 'missing: %s\n' "$1" >&2; exit 1; }; } -assert 'GEISA system state: 2026-07-29 12:23:43 UTC' -assert 'Hostname: geisa-imx93' -assert 'GEISA account: uid=999(geisa) gid=999(geisa) groups=999(geisa),995(ethosu)' -assert 'Cgroups: cgroup2fs controllers=cpuset cpu io memory pids' -assert 'Network: end0 UP 192.0.2.188/24; lxcbr0 DOWN ' -assert 'Thermal: cpu-thermal 63.4 C' -assert 'Alpha (com.example.alpha) state=running' -assert 'Systemd: failed=0' -grep -F 'Filesystem Size Used Avail Use% Mounted on' "$output" >/dev/null -grep -F 'Swap: 0 0 0' "$output" >/dev/null -grep -F 'geisa-app-alpha RUNNING' "$output" >/dev/null - -line_number() { - line=$(grep -n -m1 -F "$1" "$output" | cut -d: -f1) - [ -n "$line" ] || { - echo "missing output marker: $1" >&2 - exit 1 - } - printf '%s\n' "$line" -} - -assert_before() { - first=$(line_number "$1") - second=$(line_number "$2") - - [ "$first" -lt "$second" ] || { - echo "output order error: '$1' must precede '$2'" >&2 - exit 1 - } -} - -assert_before 'Hostname: geisa-imx93' 'Cgroups: cgroup2fs' -assert_before 'Cgroups: cgroup2fs' 'GEISA account:' -assert_before 'GEISA account:' 'Network:' -assert_before 'Network:' 'Thermal:' -assert_before 'Thermal:' 'LXC:' -assert_before 'LXC:' 'Managed applications:' -assert_before 'Managed applications:' 'Systemd: failed=0' -assert_before 'Systemd: failed=0' 'Filesystems:' -assert_before 'Filesystems:' 'Resources:' - -# A heading without a container row is an explicit empty LXC state. -make_tool lxc-ls <<'EOF' -#!/bin/sh -printf '%s\n' 'NAME STATE AUTOSTART GROUPS IPV4 IPV6 UNPRIVILEGED' -EOF -PATH="$fake:$PATH" SYSFS_ROOT="$work/sys" PROC_ROOT="$work/proc" GEISA_STATE_ROOT="$work/state" \ - "$script" --once >"$work/no-lxc.out" -grep -Fxq 'none' "$work/no-lxc.out" - -# Optional facilities must degrade independently. -PATH="$fake:$PATH" SYSFS_ROOT="$work/no-thermal" PROC_ROOT="$work/proc" GEISA_STATE_ROOT="$work/no-runtime" \ - "$script" --once >"$work/optional.out" -grep -Fqx 'Thermal: unavailable' "$work/optional.out" >/dev/null -grep -Fqx 'runtime not installed or registry unavailable' "$work/optional.out" >/dev/null - -# Refresh redirected to a file must not emit terminal controls or call clear. -PATH="$fake:$PATH" SYSFS_ROOT="$work/sys" PROC_ROOT="$work/proc" GEISA_STATE_ROOT="$work/state" \ - INTERVAL=1 timeout 2 "$script" >"$work/refresh.out" 2>"$work/refresh.err" || true -[ ! -s "$work/refresh.err" ] -[ "$(grep -c '^GEISA system state:' "$work/refresh.out")" -ge 1 ] -! grep -q "$(printf '\033')" "$work/refresh.out" - -printf 'geisa-system-state fixture tests: PASS\n' diff --git a/platforms/nxp-imx93-yocto/sources/meta-security b/platforms/nxp-imx93-yocto/sources/meta-security new file mode 160000 index 0000000..784ca4b --- /dev/null +++ b/platforms/nxp-imx93-yocto/sources/meta-security @@ -0,0 +1 @@ +Subproject commit 784ca4b6584101e971b2d5d76ec7b716ad1301b5