diff --git a/MODULE.bazel.lock b/MODULE.bazel.lock index 86ff2e413d2..05db72393df 100644 --- a/MODULE.bazel.lock +++ b/MODULE.bazel.lock @@ -95,7 +95,8 @@ "https://bcr.bazel.build/modules/bazel_lib/3.0.0-beta.1/MODULE.bazel": "407729e232f611c3270005b016b437005daa7b1505826798ea584169a476e878", "https://bcr.bazel.build/modules/bazel_lib/3.0.0-rc.0/MODULE.bazel": "d6e00979a98ac14ada5e31c8794708b41434d461e7e7ca39b59b765e6d233b18", "https://bcr.bazel.build/modules/bazel_lib/3.0.0/MODULE.bazel": "22b70b80ac89ad3f3772526cd9feee2fa412c2b01933fea7ed13238a448d370d", - "https://bcr.bazel.build/modules/bazel_lib/3.0.0/source.json": "895f21909c6fba01d7c17914bb6c8e135982275a1b18cdaa4e62272217ef1751", + "https://bcr.bazel.build/modules/bazel_lib/3.7.1/MODULE.bazel": "b6fd9b2f8fab956420c11836f416efac4a70e20804ae384ebe62773a4ed70046", + "https://bcr.bazel.build/modules/bazel_lib/3.7.1/source.json": "635fdaa28b50c04febc5e60ef51bc913d3bc87bfbaac7045449273c2341648cb", "https://bcr.bazel.build/modules/bazel_skylib/1.0.3/MODULE.bazel": "bcb0fd896384802d1ad283b4e4eb4d718eebd8cb820b0a2c3a347fb971afd9d8", "https://bcr.bazel.build/modules/bazel_skylib/1.1.1/MODULE.bazel": "1add3e7d93ff2e6998f9e118022c84d163917d912f5afafb3058e3d2f1545b5e", "https://bcr.bazel.build/modules/bazel_skylib/1.2.0/MODULE.bazel": "44fe84260e454ed94ad326352a698422dbe372b21a1ac9f3eab76eb531223686", @@ -674,6 +675,7 @@ "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/bazel_lib/3.0.0-beta.1/MODULE.bazel": "not found", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/bazel_lib/3.0.0-rc.0/MODULE.bazel": "not found", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/bazel_lib/3.0.0/MODULE.bazel": "not found", + "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/bazel_lib/3.7.1/MODULE.bazel": "not found", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/bazel_skylib/1.0.3/MODULE.bazel": "not found", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/bazel_skylib/1.1.1/MODULE.bazel": "not found", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/bazel_skylib/1.2.0/MODULE.bazel": "not found", @@ -1025,8 +1027,10 @@ "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_python_basics/0.3.4/source.json": "28ed0207a16f8498a84fae4983fa73060805003a4fbd68c6d749e2f1cc14601f", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_qnx_unit_tests/0.2.0/MODULE.bazel": "aaffff67916dd058737aac8e04368f12b214e7646ff58adbab48e6429d1a5410", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_qnx_unit_tests/0.2.0/source.json": "c40a614fd88beab7cb65b8640debd44eff3fbc32a7839734ef1112f265d2eeef", - "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rules_imagefs/0.0.1/MODULE.bazel": "1778b64b50002e31f8531bc4cc63c454eb830e769af5034825361c5d408edf68", - "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rules_imagefs/0.0.1/source.json": "ddb7e72bcda5e6ed3ac67d0c628c837204bb52f051fce55e349ee7c3fdc18714", + "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rules_imagefs/0.0.3/MODULE.bazel": "d87fcd3485438284fa96d6a5a81923d6b6672468947423517cc43c4d7692ca6a", + "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rules_imagefs/0.0.4/MODULE.bazel": "e0a846244a2bb99939d8c3bde2d3d6b5a5c868e0514aeb6af37657d39622e68d", + "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rules_imagefs/0.1.0/MODULE.bazel": "7964f78b6a92aebc38916dedbfb5f011d4fa4c385d86f7612c39c7a423b012cc", + "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rules_imagefs/0.1.0/source.json": "8aa1214aec6645a9cbbfec86b855402de2f0c42b9aa37224279a64788350a58e", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rust_policies/0.0.2/MODULE.bazel": "ade2bad4a331b02d9b7e7d9842e8de8c6fded6186486e02c4f7db5cd4b71d34d", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rust_policies/0.0.5/MODULE.bazel": "7de02547bdf121d3dedf5141b97f0fd9a545bd255ff5c7b699056b35816ffad9", "https://raw.githubusercontent.com/eclipse-score/bazel_registry/main/modules/score_rust_policies/0.0.5/source.json": "22c8bf0a5cbf7c7b06f774f3f66498e0bc14346a8b2208f7427a8fbb78a42547", @@ -1075,7 +1079,7 @@ "moduleExtensions": { "@@aspect_rules_esbuild+//esbuild:extensions.bzl%esbuild": { "general": { - "bzlTransitiveDigest": "m+1nRJvQO4i2rBVXIiwrvEKX0GAuEm4b36fgpknferw=", + "bzlTransitiveDigest": "xa0pOEfVyufb2E4901P5WFYhgbi0g5qBN03HONY+wCw=", "usagesDigest": "sj4kz7yaVclWMuWhUhSLq0bVH7+HrkWyMdODMeA7Zhw=", "recordedFileInputs": {}, "recordedDirentsInputs": {}, @@ -1222,6 +1226,11 @@ "bazel_tools", "bazel_tools" ], + [ + "bazel_lib+", + "bazel_lib", + "bazel_lib+" + ], [ "bazel_lib+", "bazel_skylib", @@ -1252,7 +1261,7 @@ }, "@@aspect_rules_js+//npm:extensions.bzl%pnpm": { "general": { - "bzlTransitiveDigest": "9x1PC0fW2ax7BkL/S2jEi77FG0ULzJX+Dnx0oaqEOs8=", + "bzlTransitiveDigest": "lxcZRv+TYKtJ/wl0igfhEGq/Z3Uctni3irkb5LCf1b8=", "usagesDigest": "kbjSw2REjlSC0HtTZDf2p+l/dmiMt3NHLoiWEXYAoQI=", "recordedFileInputs": {}, "recordedDirentsInputs": {}, @@ -1362,6 +1371,11 @@ "bazel_features_version", "bazel_features++version_extension+bazel_features_version" ], + [ + "bazel_lib+", + "bazel_lib", + "bazel_lib+" + ], [ "bazel_lib+", "bazel_skylib", @@ -2366,7 +2380,7 @@ }, "@@rules_distroless+//apt:extensions.bzl%apt": { "general": { - "bzlTransitiveDigest": "hV7bNlvh2Cx/k7WkraMRnZaOdEcU63CBNVQZBtp2vHo=", + "bzlTransitiveDigest": "JeghnHp8g69GVW+YOpl7vD3YRaZmylDr+E+iuARG86I=", "usagesDigest": "PGGts4dHdQebqbjPFpqdLfQGezTaqPJ0ZOpmBcqbhSs=", "recordedFileInputs": { "@@score_tooling+//third_party/docs_runtime/manifest.yaml": "f8bd762e0dcaf3150504eca8dfd60819fc3be428d3a8b58d1d9cc52d68e16a45", @@ -11360,30 +11374,32 @@ }, "@@score_rules_imagefs+//extensions:imagefs.bzl%imagefs": { "general": { - "bzlTransitiveDigest": "ETu3pvB97GXc6raWaXa9PVv5dTxGA7Z/vRebXiZn+Bs=", + "bzlTransitiveDigest": "AhldzzceHQweCskTyocFKGDFKZfW2t5IdpfsFJV4S9g=", "usagesDigest": "/TmbRDKbrKvzgUh1kgwmBgikEuIonP0fOz164yCxbIw=", "recordedFileInputs": {}, "recordedDirentsInputs": {}, "envVariables": {}, "generatedRepoSpecs": { "score_qnx_x86_64_ifs_toolchain": { - "repoRuleId": "@@score_rules_imagefs+//rules/qnx:imagefs_toolchain.bzl%imagefs_toolchain", + "repoRuleId": "@@score_rules_imagefs+//rules:imagefs_toolchain.bzl%imagefs_toolchain", "attributes": { "tc_cpu": "x86_64", "tc_os": "qnx", "tc_pkg_repo": "'@@score_bazel_cpp_toolchains++gcc+score_qcc_x86_64_toolchain_pkg'", "sdp_version": "8.0.0", - "tc_type": "ifs" + "tc_type": "ifs", + "coreutils_pkg_repo": "" } }, "score_qnx_aarch64_ifs_toolchain": { - "repoRuleId": "@@score_rules_imagefs+//rules/qnx:imagefs_toolchain.bzl%imagefs_toolchain", + "repoRuleId": "@@score_rules_imagefs+//rules:imagefs_toolchain.bzl%imagefs_toolchain", "attributes": { "tc_cpu": "aarch64", "tc_os": "qnx", "tc_pkg_repo": "'@@score_bazel_cpp_toolchains++gcc+score_qcc_aarch64_toolchain_pkg'", "sdp_version": "8.0.0", - "tc_type": "ifs" + "tc_type": "ifs", + "coreutils_pkg_repo": "" } } }, @@ -11398,6 +11414,16 @@ "score_qcc_x86_64_toolchain_pkg", "score_bazel_cpp_toolchains++gcc+score_qcc_x86_64_toolchain_pkg" ], + [ + "bazel_lib+", + "bazel_tools", + "bazel_tools" + ], + [ + "score_rules_imagefs+", + "bazel_lib", + "bazel_lib+" + ], [ "score_rules_imagefs+", "bazel_tools", diff --git a/bazel_common/score_images.MODULE.bazel b/bazel_common/score_images.MODULE.bazel index 6b79fc38b71..fada5caf986 100644 --- a/bazel_common/score_images.MODULE.bazel +++ b/bazel_common/score_images.MODULE.bazel @@ -50,17 +50,7 @@ http_file( url = "https://github.com/Elektrobit/eb_corbos_toolkit/releases/download/v2.0.0-beta2/fastdev-trixie-ebclfsa-ebcl-qemuarm64.tar.gz", ) -bazel_dep(name = "score_rules_imagefs", version = "0.0.1") - -# Pin score_rules_imagefs to 0.0.1. The bumped score_communication pulls in -# score_qnx_unit_tests@0.2.0 which requests score_rules_imagefs@0.0.3, but 0.0.3 -# drops the `ext_repo_maping` attribute used by our QNX image build files. Force -# 0.0.1 so the reference integration image definitions keep working without a -# larger image-definition migration. -single_version_override( - module_name = "score_rules_imagefs", - version = "0.0.1", -) +bazel_dep(name = "score_rules_imagefs", version = "0.1.0") imagefs = use_extension("@score_rules_imagefs//extensions:imagefs.bzl", "imagefs", dev_dependency = True) imagefs.toolchain( diff --git a/docs/integration_process/step_4_platforms.rst b/docs/integration_process/step_4_platforms.rst index 606eef717c6..4719eb87768 100644 --- a/docs/integration_process/step_4_platforms.rst +++ b/docs/integration_process/step_4_platforms.rst @@ -184,30 +184,36 @@ must always be present — you wire it straight into each image's build description instead. Unlike the showcase route, **this is per-image work: you repeat it for every image you target** (Linux, QNX, AutoSD, EBcLfSA). -The reference example is the ``datarouter``. In the QNX image it is added as a -source of the image target and exposed to the image's build description via a -location mapping, then placed into the filesystem by ``system.build``: +The reference example is the ``datarouter``. In the QNX images its destination +path, permissions and owner are declared as a ``pkg_files`` target which is then +listed in the image's ``srcs``; ``score_rules_imagefs`` generates the matching +``mkifs`` directives, so nothing has to be added to ``system.build``: .. code-block:: python # images/qnx_x86_64/build/BUILD + pkg_files( + name = "datarouter", + srcs = ["@score_logging//score/datarouter"], + attributes = pkg_attributes(mode = "0777"), + prefix = "usr/bin/datarouter", + ) + qnx_ifs( name = "init", srcs = [ # ... - "//showcases", - "@score_logging//score/datarouter", - "//feature_integration_tests/configs/datarouter:etc_configs", + ":datarouter", ], - ext_repo_maping = { - "BUNDLE_PATH": "$(location //showcases:showcases)", - "DATAROUTER_PATH": "$(location @score_logging//score/datarouter:datarouter)", - }, + build_file = "init.build", + extra_build_files = ["system.build"], ) -See `images/qnx_x86_64/build/BUILD `_ and the -matching deployment lines in -`images/qnx_x86_64/build/system.build `_ +Note that ``qnx_ifs`` rejects anything in ``srcs`` that does not provide a +``rules_pkg`` provider, so a plain ``filegroup`` or a bare label will not work - +wrap it in ``pkg_files``. + +See `images/qnx_x86_64/build/BUILD `_ for the full picture, and repeat the equivalent wiring in the other images you need (`images/linux_x86_64 `_, `images/autosd `_, diff --git a/images/qnx_aarch64/build/BUILD b/images/qnx_aarch64/build/BUILD index ca5c4d35043..f6fdea7c032 100644 --- a/images/qnx_aarch64/build/BUILD +++ b/images/qnx_aarch64/build/BUILD @@ -11,62 +11,148 @@ # SPDX-License-Identifier: Apache-2.0 # ******************************************************************************* +load("@rules_pkg//pkg:mappings.bzl", "REMOVE_BASE_DIRECTORY", "pkg_attributes", "pkg_files") load("@score_rules_imagefs//rules/qnx:ifs.bzl", "qnx_ifs") -filegroup( - name = "scripts", +# score_rules_imagefs derives the mkifs placement directives from these +# rules_pkg targets, so the destination path, permissions and owner of every +# Bazel-provided file are declared here instead of in system.build. + +pkg_files( + name = "etc_scripts", srcs = [ + "//images/qnx_aarch64/configs:network_setup.sh", + "//images/qnx_aarch64/configs:network_setup_dhcp.sh", "//images/qnx_aarch64/configs:startup.sh", ], + attributes = pkg_attributes(mode = "0700"), + prefix = "etc", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "etc_network_capture", + srcs = ["//images/qnx_aarch64/configs:network_capture.sh"], + attributes = pkg_attributes(mode = "0755"), + prefix = "etc", + renames = {"//images/qnx_aarch64/configs:network_capture.sh": "network_capture"}, visibility = ["//visibility:private"], ) -filegroup( - name = "configs", +# mkifs resolves a bare filename against its default /proc/boot prefix, which is +# how these were written before; the prefix is explicit now because +# score_rules_imagefs always emits an absolute destination. startup.sh references +# these by their /proc/boot path. +pkg_files( + name = "boot_configs", + srcs = ["//images/qnx_aarch64/configs:qcrypto.conf"], + attributes = pkg_attributes(mode = "0444"), + prefix = "proc/boot", + visibility = ["//visibility:private"], +) + +# These four carried no attribute block before, which made mkifs inherit the +# host file mode. All four are 0644 in git; pin it. +pkg_files( + name = "etc_identity", srcs = [ - "//images/qnx_aarch64/configs:dhcpcd.conf", "//images/qnx_aarch64/configs:group", "//images/qnx_aarch64/configs:hostname", - "//images/qnx_aarch64/configs:network_capture.sh", - "//images/qnx_aarch64/configs:network_setup.sh", - "//images/qnx_aarch64/configs:network_setup_dhcp.sh", "//images/qnx_aarch64/configs:passwd", "//images/qnx_aarch64/configs:profile", - "//images/qnx_aarch64/configs:qcrypto.conf", + ], + attributes = pkg_attributes(mode = "0644"), + prefix = "etc", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "etc_dhcpcd", + srcs = ["//images/qnx_aarch64/configs:dhcpcd.conf"], + attributes = pkg_attributes(mode = "0644"), + prefix = "etc", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "ssh_config", + srcs = ["//images/qnx_aarch64/configs:sshd_config"], + attributes = pkg_attributes(mode = "0444"), + prefix = "var/ssh", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "ssh_host_keys", + srcs = [ "//images/qnx_aarch64/configs:ssh_host_rsa_key", "//images/qnx_aarch64/configs:ssh_host_rsa_key.pub", - "//images/qnx_aarch64/configs:sshd_config", ], + attributes = pkg_attributes( + gid = 0, + mode = "0400", + uid = 0, + ), + prefix = "var/ssh", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "etc_comm_configs", + srcs = ["//feature_integration_tests/configs:etc_configs"], + attributes = pkg_attributes(mode = "0777"), + prefix = "etc", visibility = ["//visibility:private"], ) +pkg_files( + name = "datarouter", + srcs = ["@score_logging//score/datarouter"], + attributes = pkg_attributes(mode = "0777"), + prefix = "usr/bin/datarouter", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "datarouter_configs", + srcs = ["//feature_integration_tests/configs/datarouter:etc_configs"], + attributes = pkg_attributes(mode = "0644"), + prefix = "usr/bin/datarouter/etc", + visibility = ["//visibility:private"], +) + +# REMOVE_BASE_DIRECTORY drops the bundle's contents at the image root, which is +# what `[perms=777] / = ${BUNDLE_PATH}` did. +pkg_files( + name = "showcases", + srcs = ["//showcases"], + attributes = pkg_attributes(mode = "0777"), + renames = {"//showcases": REMOVE_BASE_DIRECTORY}, + visibility = ["//visibility:private"], +) + +# Not built or booted by CI. QNX SDP 8.0.0 ships no generic QEMU-virt startup +# binary, so init.build's `startup-virt` cannot resolve without a target BSP. +# Tagged manual so wildcard builds skip it. qnx_ifs( name = "init", srcs = [ - ":configs", - ":scripts", - ":system.build", - ":system_dir", - "//feature_integration_tests/configs:etc_configs", - "//feature_integration_tests/configs/datarouter:etc_configs", - "//showcases", - "@score_logging//score/datarouter", - "@score_persistency//tests/test_scenarios/cpp:test_scenarios", + ":boot_configs", + ":datarouter", + ":datarouter_configs", + ":etc_comm_configs", + ":etc_dhcpcd", + ":etc_identity", + ":etc_network_capture", + ":etc_scripts", + ":showcases", + ":ssh_config", + ":ssh_host_keys", ], build_file = "init.build", - ext_repo_maping = { - "BUNDLE_PATH": "$(location //showcases:showcases)", - "DATAROUTER_PATH": "$(location @score_logging//score/datarouter:datarouter)", - }, + extra_build_files = ["system.build"], + tags = ["manual"], visibility = [ "//visibility:public", ], ) - -filegroup( - name = "system_dir", - srcs = [ - "init.build", - "system.build", - ], -) diff --git a/images/qnx_aarch64/build/init.build b/images/qnx_aarch64/build/init.build index 3f8be6768df..781ae14fe15 100644 --- a/images/qnx_aarch64/build/init.build +++ b/images/qnx_aarch64/build/init.build @@ -95,4 +95,3 @@ libslog2.so.1 # System logging library (slog2_* functions) # Orchestrator example needed [type=link] /data=/tmp_ram -[+include] ${MAIN_BUILD_FILE_DIR}/system.build # Include additional system build configurations diff --git a/images/qnx_aarch64/build/system.build b/images/qnx_aarch64/build/system.build index 190f56fa7ff..6fe04034fb4 100644 --- a/images/qnx_aarch64/build/system.build +++ b/images/qnx_aarch64/build/system.build @@ -233,57 +233,16 @@ pci/pci_debug2.so # Enhanced PCI debugging support [gid=0 uid=0 dperms=755 type=dir] /var/chroot/sshd # SSH chroot directory for privilege separation [gid=0 uid=0 dperms=700 type=dir] /var/ssh # SSH configuration and key storage directory - -############################################# -### SCRIPTS ### -############################################# -# System startup and initialization scripts -[perms=700] /etc/startup.sh = ${MAIN_BUILD_FILE_DIR}/../configs/startup.sh # Main system startup script -[perms=700] /etc/network_setup.sh = ${MAIN_BUILD_FILE_DIR}/../configs/network_setup.sh # Network configuration script -[perms=700] /etc/network_setup_dhcp.sh = ${MAIN_BUILD_FILE_DIR}/../configs/network_setup_dhcp.sh # Network configuration script -[perms=755] /etc/network_capture = ${MAIN_BUILD_FILE_DIR}/../configs/network_capture.sh # Network packet capture utility - - -############################################# -### CONFIGURATION FILES ### -############################################# -# This section defines critical configuration files that control system -# behavior, hardware access, security policies, and user environment setup. - -[perms=0444] qcrypto.conf = ${MAIN_BUILD_FILE_DIR}/../configs/qcrypto.conf # QNX cryptographic library configuration - -# System hostname configuration -/etc/hostname = ${MAIN_BUILD_FILE_DIR}/../configs/hostname # System hostname definition file -/etc/profile = ${MAIN_BUILD_FILE_DIR}/../configs/profile - -# System user and group databases -/etc/passwd = ${MAIN_BUILD_FILE_DIR}/../configs/passwd # User account database with login information -/etc/group = ${MAIN_BUILD_FILE_DIR}/../configs/group # Group membership database - - -############################################# -### SSH CONFIGURATION ### -############################################# -# SSH server configuration (no static host keys - generated at runtime) -[perms=444] /var/ssh/sshd_config = ${MAIN_BUILD_FILE_DIR}/../configs/sshd_config # SSH daemon configuration file - -[uid=0 gid=0 perms=400] /var/ssh/ssh_host_rsa_key = ${MAIN_BUILD_FILE_DIR}/../configs/ssh_host_rsa_key # SSH server private key -[uid=0 gid=0 perms=400] /var/ssh/ssh_host_rsa_key.pub = ${MAIN_BUILD_FILE_DIR}/../configs/ssh_host_rsa_key.pub # SSH server public key - -# DHCP client configuration -[perms=644] /etc/dhcpcd.conf = ${MAIN_BUILD_FILE_DIR}/../configs/dhcpcd.conf # DHCP client configuration file - -# Communication configuration files -[perms=777] /etc/logging.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/etc/logging.json -[perms=777] /etc/mw_com_config.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/etc/mw_com_config.json - # Executable files from external repositories [perms=777] /scrample = ${SCRAMPLE_PATH} [perms=777] /cpp_tests_persistency = ${CPP_TEST_SCENARIOS_PATH} -[perms=777] /usr/bin/datarouter/datarouter = ${DATAROUTER_PATH} -[perms=644] /usr/bin/datarouter/etc/logging.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/datarouter/etc/logging.json -[perms=644] /usr/bin/datarouter/etc/log-channels.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/datarouter/etc/log-channels.json - -# Common showcases bundle -[perms=777] / = ${BUNDLE_PATH} +############################################# +### BAZEL-PROVIDED CONTENT ### +############################################# +# Scripts, configuration files, SSH host keys, the datarouter binary and the +# showcases bundle are declared as rules_pkg targets in +# //images/qnx_aarch64/build:BUILD. +# score_rules_imagefs turns those into mkifs directives in +# init_pkg_content.build, which its generated entrypoint includes after this +# file - so the directory entries above still precede the files they hold. diff --git a/images/qnx_x86_64/build/BUILD b/images/qnx_x86_64/build/BUILD index 4edc7efc20e..bfbf091ebd2 100644 --- a/images/qnx_x86_64/build/BUILD +++ b/images/qnx_x86_64/build/BUILD @@ -11,64 +11,148 @@ # SPDX-License-Identifier: Apache-2.0 # ******************************************************************************* +load("@rules_pkg//pkg:mappings.bzl", "REMOVE_BASE_DIRECTORY", "pkg_attributes", "pkg_files") load("@score_rules_imagefs//rules/qnx:ifs.bzl", "qnx_ifs") -filegroup( - name = "scripts", +# score_rules_imagefs derives the mkifs placement directives from these +# rules_pkg targets, so the destination path, permissions and owner of every +# Bazel-provided file are declared here instead of in system.build. + +pkg_files( + name = "etc_scripts", srcs = [ + "//images/qnx_x86_64/configs:network_setup.sh", + "//images/qnx_x86_64/configs:network_setup_dhcp.sh", "//images/qnx_x86_64/configs:startup.sh", ], + attributes = pkg_attributes(mode = "0700"), + prefix = "etc", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "etc_network_capture", + srcs = ["//images/qnx_x86_64/configs:network_capture.sh"], + attributes = pkg_attributes(mode = "0755"), + prefix = "etc", + renames = {"//images/qnx_x86_64/configs:network_capture.sh": "network_capture"}, visibility = ["//visibility:private"], ) -filegroup( - name = "configs", +# mkifs resolves a bare filename against its default /proc/boot prefix, which is +# how these were written before; the prefix is explicit now because +# score_rules_imagefs always emits an absolute destination. startup.sh and +# pci_server.cfg reference these by their /proc/boot path. +pkg_files( + name = "boot_configs", + srcs = [ + "//images/qnx_x86_64/configs:pci_hw.cfg", + "//images/qnx_x86_64/configs:pci_server.cfg", + "//images/qnx_x86_64/configs:qcrypto.conf", + ], + attributes = pkg_attributes(mode = "0444"), + prefix = "proc/boot", + visibility = ["//visibility:private"], +) + +# These four carried no attribute block before, which made mkifs inherit the +# host file mode. All four are 0644 in git; pin it. +pkg_files( + name = "etc_identity", srcs = [ - "//images/qnx_x86_64/configs:dhcpcd.conf", "//images/qnx_x86_64/configs:group", "//images/qnx_x86_64/configs:hostname", - "//images/qnx_x86_64/configs:network_capture.sh", - "//images/qnx_x86_64/configs:network_setup.sh", - "//images/qnx_x86_64/configs:network_setup_dhcp.sh", "//images/qnx_x86_64/configs:passwd", - "//images/qnx_x86_64/configs:pci_hw.cfg", - "//images/qnx_x86_64/configs:pci_server.cfg", "//images/qnx_x86_64/configs:profile", - "//images/qnx_x86_64/configs:qcrypto.conf", + ], + attributes = pkg_attributes(mode = "0644"), + prefix = "etc", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "etc_dhcpcd", + srcs = ["//images/qnx_x86_64/configs:dhcpcd.conf"], + attributes = pkg_attributes(mode = "0644"), + prefix = "etc", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "ssh_config", + srcs = ["//images/qnx_x86_64/configs:sshd_config"], + attributes = pkg_attributes(mode = "0444"), + prefix = "var/ssh", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "ssh_host_keys", + srcs = [ "//images/qnx_x86_64/configs:ssh_host_rsa_key", "//images/qnx_x86_64/configs:ssh_host_rsa_key.pub", - "//images/qnx_x86_64/configs:sshd_config", ], + attributes = pkg_attributes( + gid = 0, + mode = "0400", + uid = 0, + ), + prefix = "var/ssh", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "etc_comm_configs", + srcs = ["//feature_integration_tests/configs:etc_configs"], + attributes = pkg_attributes(mode = "0777"), + prefix = "etc", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "datarouter", + srcs = ["@score_logging//score/datarouter"], + attributes = pkg_attributes(mode = "0777"), + prefix = "usr/bin/datarouter", + visibility = ["//visibility:private"], +) + +pkg_files( + name = "datarouter_configs", + srcs = ["//feature_integration_tests/configs/datarouter:etc_configs"], + attributes = pkg_attributes(mode = "0644"), + prefix = "usr/bin/datarouter/etc", + visibility = ["//visibility:private"], +) + +# REMOVE_BASE_DIRECTORY drops the bundle's contents at the image root, which is +# what `[perms=777] / = ${BUNDLE_PATH}` did. +pkg_files( + name = "showcases", + srcs = ["//showcases"], + attributes = pkg_attributes(mode = "0777"), + renames = {"//showcases": REMOVE_BASE_DIRECTORY}, visibility = ["//visibility:private"], ) qnx_ifs( name = "init", srcs = [ - ":configs", - ":scripts", - ":system.build", - ":system_dir", - "//feature_integration_tests/configs:etc_configs", - "//feature_integration_tests/configs/datarouter:etc_configs", - "//showcases", - "@score_logging//score/datarouter", - "@score_persistency//score/kvs/tests/test_scenarios/cpp:test_scenarios", + ":boot_configs", + ":datarouter", + ":datarouter_configs", + ":etc_comm_configs", + ":etc_dhcpcd", + ":etc_identity", + ":etc_network_capture", + ":etc_scripts", + ":showcases", + ":ssh_config", + ":ssh_host_keys", ], build_file = "init.build", - ext_repo_maping = { - "BUNDLE_PATH": "$(location //showcases:showcases)", - "DATAROUTER_PATH": "$(location @score_logging//score/datarouter:datarouter)", - }, + extra_build_files = ["system.build"], visibility = [ "//visibility:public", ], ) - -filegroup( - name = "system_dir", - srcs = [ - "init.build", - "system.build", - ], -) diff --git a/images/qnx_x86_64/build/init.build b/images/qnx_x86_64/build/init.build index fdc1d273390..5d6044082d6 100644 --- a/images/qnx_x86_64/build/init.build +++ b/images/qnx_x86_64/build/init.build @@ -98,4 +98,3 @@ devb-eide # Block device driver for IDE/SATA hard drive # Orchestrator example needed [type=link] /data=/tmp_ram -[+include] ${MAIN_BUILD_FILE_DIR}/system.build # Include additional system build configurations diff --git a/images/qnx_x86_64/build/system.build b/images/qnx_x86_64/build/system.build index 16f55a4607f..41cf9750ed7 100644 --- a/images/qnx_x86_64/build/system.build +++ b/images/qnx_x86_64/build/system.build @@ -234,60 +234,16 @@ pci/pci_debug2.so # Enhanced PCI debugging support [gid=0 uid=0 dperms=755 type=dir] /var/chroot/sshd # SSH chroot directory for privilege separation [gid=0 uid=0 dperms=700 type=dir] /var/ssh # SSH configuration and key storage directory - -############################################# -### SCRIPTS ### -############################################# -# System startup and initialization scripts -[perms=700] /etc/startup.sh = ${MAIN_BUILD_FILE_DIR}/../configs/startup.sh # Main system startup script -[perms=700] /etc/network_setup.sh = ${MAIN_BUILD_FILE_DIR}/../configs/network_setup.sh # Network configuration script -[perms=700] /etc/network_setup_dhcp.sh = ${MAIN_BUILD_FILE_DIR}/../configs/network_setup_dhcp.sh # Network configuration script -[perms=755] /etc/network_capture = ${MAIN_BUILD_FILE_DIR}/../configs/network_capture.sh # Network packet capture utility - - -############################################# -### CONFIGURATION FILES ### -############################################# -# This section defines critical configuration files that control system -# behavior, hardware access, security policies, and user environment setup. - -[perms=0444] pci_server.cfg = ${MAIN_BUILD_FILE_DIR}/../configs/pci_server.cfg # PCI server configuration -[perms=0444] pci_hw.cfg = ${MAIN_BUILD_FILE_DIR}/../configs/pci_hw.cfg # PCI hardware configuration -[perms=0444] qcrypto.conf = ${MAIN_BUILD_FILE_DIR}/../configs/qcrypto.conf # QNX cryptographic library configuration - -# System hostname configuration -/etc/hostname = ${MAIN_BUILD_FILE_DIR}/../configs/hostname # System hostname definition file -/etc/profile = ${MAIN_BUILD_FILE_DIR}/../configs/profile - -# System user and group databases -/etc/passwd = ${MAIN_BUILD_FILE_DIR}/../configs/passwd # User account database with login information -/etc/group = ${MAIN_BUILD_FILE_DIR}/../configs/group # Group membership database - - -############################################# -### SSH CONFIGURATION ### -############################################# -# SSH server configuration (no static host keys - generated at runtime) -[perms=444] /var/ssh/sshd_config = ${MAIN_BUILD_FILE_DIR}/../configs/sshd_config # SSH daemon configuration file - -[uid=0 gid=0 perms=400] /var/ssh/ssh_host_rsa_key = ${MAIN_BUILD_FILE_DIR}/../configs/ssh_host_rsa_key # SSH server private key -[uid=0 gid=0 perms=400] /var/ssh/ssh_host_rsa_key.pub = ${MAIN_BUILD_FILE_DIR}/../configs/ssh_host_rsa_key.pub # SSH server public key - -# DHCP client configuration -[perms=644] /etc/dhcpcd.conf = ${MAIN_BUILD_FILE_DIR}/../configs/dhcpcd.conf # DHCP client configuration file - -# Communication configuration files -[perms=777] /etc/logging.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/etc/logging.json -[perms=777] /etc/mw_com_config.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/etc/mw_com_config.json - # Executable files from external repositories [perms=777] /scrample = ${SCRAMPLE_PATH} [perms=777] /cpp_tests_persistency = ${CPP_TEST_SCENARIOS_PATH} -[perms=777] /usr/bin/datarouter/datarouter = ${DATAROUTER_PATH} -[perms=644] /usr/bin/datarouter/etc/logging.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/datarouter/etc/logging.json -[perms=644] /usr/bin/datarouter/etc/log-channels.json = ${MAIN_BUILD_FILE_DIR}/../../../feature_integration_tests/configs/datarouter/etc/log-channels.json - -# Common showcases bundle -[perms=777] / = ${BUNDLE_PATH} - +############################################# +### BAZEL-PROVIDED CONTENT ### +############################################# +# Scripts, configuration files, SSH host keys, the datarouter binary and the +# showcases bundle are declared as rules_pkg targets in +# //images/qnx_x86_64/build:BUILD. +# score_rules_imagefs turns those into mkifs directives in +# init_pkg_content.build, which its generated entrypoint includes after this +# file - so the directory entries above still precede the files they hold.