Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
82 commits
Select commit Hold shift + click to select a range
57d4102
fix(waydroid): lxc ThinLTO configure and python3-gbinder Cython 3
May 19, 2026
f2778ce
feat(waydroid): provision Android images outside OSTree
ajlennon Sep 4, 2026
aade8ff
fix(waydroid): require Etnaviv on Jaguar screen
ajlennon Sep 4, 2026
871146d
fix(waydroid): allow Etnaviv without Vulkan on Jaguar screen
ajlennon Sep 4, 2026
e391784
fix(waydroid): use executable LXC stop hook
ajlennon Sep 6, 2026
b949eaa
feat(waydroid): boot Android UI on Jaguar screen
ajlennon Sep 6, 2026
dc04e74
fix(waydroid): use landscape splash for rotated output
ajlennon Sep 7, 2026
41df2bb
feat(demo): add Jaguar Waydroid GPU baseline
ajlennon Sep 7, 2026
935b490
docs(release): distinguish functional and source baselines
ajlennon Sep 7, 2026
f760695
docs(release): reject target 2888 watchdog experiment
ajlennon Sep 7, 2026
306e43c
docs(release): record bounded reboot validation
ajlennon Sep 7, 2026
6202824
bsp: fix existing Jaguar U-Boot patches
ajlennon Sep 12, 2026
7c184c7
ci: enforce layer adoption regression gate
ajlennon Sep 11, 2026
82f2c51
ci: fix layer gate expressions
ajlennon Sep 11, 2026
6b8e574
ci: bound layer gate build concurrency
ajlennon Sep 11, 2026
71c01cd
ci: use current Actions runtimes
ajlennon Sep 11, 2026
c73dd4b
ci: emit layer matrix without jq
ajlennon Sep 11, 2026
58bb309
ci: route Yocto jobs to capable runner
ajlennon Sep 11, 2026
ce0b9da
ci: strengthen layer adoption evidence
ajlennon Sep 11, 2026
372d90c
ci: preserve protected layer adoption tuples
ajlennon Sep 11, 2026
9d6bb5a
ci: test protected layer adoption matrix
ajlennon Sep 11, 2026
06f1536
ci: protect exact product feature tuples
ajlennon Sep 12, 2026
b9207b9
ci: exercise signing in layer adoption gate
ajlennon Sep 12, 2026
303978b
ci: use valid job-level key path
ajlennon Sep 12, 2026
4b2cfa7
ci: bound layer gate disk usage
ajlennon Sep 12, 2026
5cf9737
ci: consolidate layer adoption regression on ai-tools
ajlennon Sep 12, 2026
28be102
ci: run container steps with bash
ajlennon Sep 12, 2026
0ba5fa3
ci: keep kas overlay inside worktree
ajlennon Sep 12, 2026
dc1079d
ci: quote layer state normalisation safely
ajlennon Sep 12, 2026
d58b88a
ci: replay captured command failures
ajlennon Sep 12, 2026
4998160
ci: initialize protected layer submodules
ajlennon Sep 12, 2026
4e07c3b
ci: initialize protected layer worktrees
ajlennon Sep 12, 2026
aba0a4d
ci: share kas worktree preparation
ajlennon Sep 12, 2026
c423642
ci: track current bitbake dependency graph
ajlennon Sep 12, 2026
67e9f6d
ci: diagnose selected environment mismatches
ajlennon Sep 12, 2026
62e7455
ci: use inode-aware disk thresholds
ajlennon Sep 12, 2026
f7bdd20
ci: bind local kas changes to adoption gate
ajlennon Sep 12, 2026
b5380f5
ci: validate kernel signing identity
ajlennon Sep 12, 2026
b08700e
ci: force test signing paths
ajlennon Sep 12, 2026
fc72fbd
ci: canonicalise layer adoption evidence
ajlennon Sep 12, 2026
fbc6f4d
ci: keep adoption gate on controlled runner
ajlennon Sep 12, 2026
531a6c2
ci: key baseline cache by capture schema
ajlennon Sep 12, 2026
9093e7a
ci: source warnings from cooker logs
ajlennon Sep 12, 2026
88a53cd
ci: normalise encoded checkout provenance
ajlennon Sep 12, 2026
f7c6d6e
ci: audit immutable baseline repair
ajlennon Sep 13, 2026
014a301
ci: include packaging baseline repair
ajlennon Sep 13, 2026
d767d4c
ci: include Handheld DTS baseline repair
ajlennon Sep 13, 2026
25e4e8a
ci: include Handheld DTS baseline repair
ajlennon Sep 13, 2026
9e66b1b
ci: retain repaired empty package baseline
ajlennon Sep 13, 2026
cc48e39
ci: include remaining DTS baseline repairs
ajlennon Sep 13, 2026
459641f
ci: make kernel warnings sstate-independent
ajlennon Sep 13, 2026
28311cb
ci: include Phasora SPDX baseline repair
ajlennon Sep 13, 2026
843ab3b
ci: match renamed license repair surface
ajlennon Sep 13, 2026
6c4a0aa
ci: treat removed warnings as improvements
ajlennon Sep 13, 2026
b47dc37
ci: shard layer adoption tuples
ajlennon Sep 13, 2026
d3be861
feat(security): confine Waydroid with host SELinux
ajlennon Sep 13, 2026
66b76bf
test(ci): add R26 Jaguar SELinux preflight tuple
ajlennon Sep 13, 2026
fc8a2a5
fix(ci): isolate local SELinux preflight signing
ajlennon Sep 13, 2026
e47e9da
ci: materialize LFS-backed KAS configs
ajlennon Sep 13, 2026
d8c44b5
merge: combine Waydroid SELinux with layer adoption gate
ajlennon Sep 13, 2026
d0f8e75
ci: protect exact Foundries product tuples
ajlennon Sep 13, 2026
3cd52a1
fix(selinux): avoid unused target toolchain
ajlennon Sep 13, 2026
e8c94ce
ci: retire Jaguar inst and Phasora tuples
ajlennon Sep 13, 2026
079fe76
ci: focus adoption gate on Jaguar screen
ajlennon Sep 13, 2026
2b98666
feat(selinux): make Waydroid policy enforcing by default
ajlennon Sep 13, 2026
667516b
merge: align focused Jaguar screen adoption gate
ajlennon Sep 13, 2026
f4a81fa
test(selinux): guard Waydroid enforcing default
ajlennon Sep 13, 2026
004cc88
chore: allow unified diff context whitespace
ajlennon Sep 13, 2026
2e5575e
test(waydroid): capture R26 board acceptance evidence
ajlennon Sep 13, 2026
ab79aa4
test(waydroid): require direct confinement evidence
ajlennon Sep 13, 2026
826a56b
merge: adopt authoritative Jaguar screen gate
ajlennon Sep 13, 2026
7e015b9
fix(selinux): isolate Waydroid policy discovery mode
ajlennon Sep 13, 2026
432afb0
ci(screen): lock SELinux discovery tuple
ajlennon Sep 13, 2026
f966469
feat(screen): retain CRA audit evidence in SELinux image
ajlennon Sep 13, 2026
10f515a
test(screen): retain CRA audit evidence path
ajlennon Sep 13, 2026
7ed1c58
fix(ci): validate audited distro by gitlink
ajlennon Sep 13, 2026
c132b61
ci: add focused tuple validation dispatch [skip ci]
ajlennon Sep 13, 2026
34cfc0c
ci: use stable connectivity probe [skip ci]
ajlennon Sep 13, 2026
e18ada2
ci: make bison docs dependency hermetic [skip ci]
ajlennon Sep 13, 2026
e2bf6f6
ci: run focused tuple on DD Hetzner [skip ci]
ajlennon Sep 13, 2026
9c7f323
ci: mirror pinned oauth2 source [skip ci]
ajlennon Sep 13, 2026
358cd2a
ci: fail fast on docker compose fetch [skip ci]
ajlennon Sep 13, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -1,5 +1,7 @@
# Shell scripts: enforce LF (avoid CRLF syntax errors on target)
*.sh text eol=lf
# Unified-diff context lines intentionally contain a single trailing space.
*.patch whitespace=-blank-at-eol

*.pdf filter=lfs diff=lfs merge=lfs -text
*.bin filter=lfs diff=lfs merge=lfs -text
Expand Down
1 change: 1 addition & 0 deletions .github/actionlint.yaml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
self-hosted-runner:
labels:
- yocto
- ai-tools
37 changes: 24 additions & 13 deletions .github/workflows/layer-adoption-gate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,17 +3,23 @@ name: Layer Adoption Gate
on:
pull_request:
branches: [main, develop]
merge_group:
types: [checks_requested]
push:
branches: [main, develop]
workflow_dispatch:
inputs:
base_sha:
description: Baseline commit to compare
required: true
tuple_id:
description: One protected tuple to build for focused development
required: true
default: imx8mm-jaguar-screen-waydroid-image

concurrency:
group: layer-adoption-${{ github.event.pull_request.number || github.ref }}
cancel-in-progress: true
group: layer-adoption-${{ github.event_name == 'merge_group' && github.event.merge_group.head_sha || github.event.pull_request.number || github.ref }}
cancel-in-progress: ${{ github.event_name != 'merge_group' }}

defaults:
run:
Expand All @@ -22,7 +28,7 @@ defaults:
jobs:
detect:
name: Detect material layer change
runs-on: [self-hosted, Linux, X64, yocto, ai-tools]
runs-on: [self-hosted, Linux, X64, yocto, dd-esl-proxmox]
outputs:
material: ${{ steps.detect.outputs.material }}
base_sha: ${{ steps.base.outputs.sha }}
Expand All @@ -35,10 +41,11 @@ jobs:
name: Resolve immutable baseline
env:
PR_BASE: ${{ github.event.pull_request.base.sha }}
MERGE_BASE: ${{ github.event.merge_group.base_sha }}
PUSH_BASE: ${{ github.event.before }}
INPUT_BASE: ${{ inputs.base_sha }}
run: |
sha="${PR_BASE:-${INPUT_BASE:-${PUSH_BASE:-}}}"
sha="${PR_BASE:-${MERGE_BASE:-${INPUT_BASE:-${PUSH_BASE:-}}}}"
if [ -z "$sha" ] || printf '%s' "$sha" | grep -Eq '^0+$'; then
sha=$(git rev-parse HEAD^)
fi
Expand All @@ -59,10 +66,14 @@ jobs:
--base '${{ steps.base.outputs.sha }}' \
--head '${{ github.sha }}' \
--github-output "$GITHUB_OUTPUT"
tuple_ids=$(python3 -c 'import json; print(json.dumps([entry["id"] for entry in json.load(open("ci/layer-adoption-tuples.json"))["tuples"]], separators=(",", ":")))')
if [ '${{ github.event_name }}' = workflow_dispatch ]; then
tuple_ids=$(python3 -c 'import json,sys; ids=[entry["id"] for entry in json.load(open("ci/layer-adoption-tuples.json"))["tuples"]]; requested=sys.argv[1]; requested in ids or sys.exit(f"unknown protected tuple: {requested}"); print(json.dumps([requested],separators=(",",":")))' '${{ inputs.tuple_id }}')
else
tuple_ids=$(python3 -c 'import json; print(json.dumps([entry["id"] for entry in json.load(open("ci/layer-adoption-tuples.json"))["tuples"]], separators=(",", ":")))')
fi
echo "tuple_ids=$tuple_ids" >> "$GITHUB_OUTPUT"
regression:
name: Existing product regression (${{ matrix.tuple_id }})
name: ${{ github.event_name == 'workflow_dispatch' && 'Development validation — baseline comparison' || 'Product readiness validation — baseline comparison' }} (${{ matrix.tuple_id }})
needs: detect
if: needs.detect.outputs.material == 'true'
strategy:
Expand All @@ -72,12 +83,12 @@ jobs:
# Each tuple is an independent shard so one failure cannot hide later
# product failures. The final Layer Adoption Gate remains the single
# branch-protection contract, and local driver runs still cover all tuples.
runs-on: [self-hosted, Linux, X64, yocto, ai-tools]
runs-on: [self-hosted, Linux, X64, yocto, dd-esl-proxmox]
container:
image: ghcr.io/siemens/kas/kas@sha256:d989add57fc441fe9e27bb2dd6ed98c5597b44c807928e35a72dc1cfbdda9abe
# Match the dedicated ai-tools runner account so BitBake's root-user
# sanity check remains active and bind-mounted cache files stay writable.
options: --privileged --platform linux/amd64 --user 1002:1002 -v /home/ghrunner/yocto-layer-adoption:/var/cache/layer-adoption
# Match the dedicated DD registration on CT101 so BitBake's root-user
# sanity check remains active and the /yocto cache stays writable.
options: --privileged --platform linux/amd64 --user 999:995 -v /yocto/yocto-layer-adoption:/var/cache/layer-adoption
env:
LAYER_ADOPTION_CACHE: /var/cache/layer-adoption
steps:
Expand Down Expand Up @@ -119,7 +130,7 @@ jobs:
candidate/scripts/validation/generate-layer-adoption-test-keys.sh "$temporary"
mv "$temporary" "$keys"
fi
- name: Build and compare every protected tuple
- name: Build and compare selected protected tuple
run: |
python3 candidate/scripts/validation/run-layer-adoption-regression.py \
--baseline baseline \
Expand Down Expand Up @@ -151,10 +162,10 @@ jobs:
done

required:
name: Layer Adoption Gate
name: ${{ github.event_name == 'workflow_dispatch' && 'Development Validation' || 'Layer Adoption Gate' }}
needs: [detect, regression]
if: always()
runs-on: [self-hosted, Linux, X64, yocto, ai-tools]
runs-on: [self-hosted, Linux, X64, yocto, dd-esl-proxmox]
steps:
- name: Enforce gate result
env:
Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
# Build outputs and layers (these are downloaded by KAS)
build/
**/out/
tmp/
tmp-glibc/
cache/
Expand Down
4 changes: 2 additions & 2 deletions ci/layer-adoption-contract.json
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
{
"schema": 1,
"reason": "Adopt the isolated NXP i.MX95 partner layer without changing any pre-existing Dynamic Devices build tuple.",
"reason": "Adopt the exact-pinned Scarthgap meta-selinux layer and enable enforcing host SELinux only for product-feature Android containers, while preserving every existing Foundries platform, signing, recovery and manufacturing tuple.",
"baseline_repairs": [
{
"base_sha": "dda54409ee27e29612c01cc1ff0eb88233ca1da5",
Expand All @@ -19,7 +19,7 @@
"recipes-bsp/upd72020x-load/upd72020x-load/LicenseRef-markusj-upd72020x-load",
"recipes-bsp/upd72020x-load/upd72020x-load_git.bb"
],
"reason": "The immutable baseline has two stale U-Boot patch contexts, mishandles intentionally empty board-scripts packages, carries three product DTS files that no longer compile against the pinned kernel, and does not expose the Phasora loader's custom license text to SPDX generation. Build both sides with the focused eight-file backport while auditing the exact old-to-new submodule transition."
"reason": "The immutable mainline baseline has two stale U-Boot patch contexts, mishandles intentionally empty board-scripts packages, carries three product DTS files that no longer compile against the pinned kernel, and does not expose the Phasora loader's custom license text to SPDX generation. Build both sides with the focused eight-file backport; the candidate BSP must contain this exact repair commit before its product-specific changes."
}
],
"allowed_deltas": {}
Expand Down
10 changes: 8 additions & 2 deletions ci/layer-adoption-tuples.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,13 @@
{
"schema": 1,
"source": {
"repository": "https://source.foundries.io/factories/dynamic-devices/ci-scripts.git",
"commit": "520e5c11dede126bd1bd35184293c20addeda380",
"file": "factory-config.yml"
},
"tuples": [
{"id": "imx8mm-jaguar-screen-image", "machine": "imx8mm-jaguar-screen", "distro": "lmp-dynamicdevices", "image": "lmp-factory-image", "config": "kas/lmp-dynamicdevices.yml", "product_features": "display flutter godot"},
{"id": "imx8mm-jaguar-screen-mfgtool", "machine": "imx8mm-jaguar-screen", "distro": "lmp-mfgtool", "image": "mfgtool-files", "config": "kas/lmp-dynamicdevices-mfgtool.yml", "product_features": ""}
{"id":"imx8mm-jaguar-screen-image","machine":"imx8mm-jaguar-screen","distro":"lmp-dynamicdevices","image":"lmp-factory-image","config":"kas/lmp-dynamicdevices.yml","product_features":"display flutter godot","variables":{}},
{"id":"imx8mm-jaguar-screen-mfgtool","machine":"imx8mm-jaguar-screen","distro":"lmp-mfgtool","image":"mfgtool-files","config":"kas/lmp-dynamicdevices-mfgtool.yml","product_features":"","variables":{}},
{"id":"imx8mm-jaguar-screen-waydroid-image","machine":"imx8mm-jaguar-screen","distro":"lmp-dynamicdevices","image":"lmp-factory-image","config":"kas/lmp-dynamicdevices.yml","product_features":"display android-container","variables":{"ACCEPT_FSL_EULA":"1","ASSEMBLE_SYSTEM_IMAGE":"0","DEV_MODE":"1","DOCKER_COMPOSE_APP":"1","PATCHTOOL":"git","WAYDROID_SELINUX_DEVELOPMENT_PERMISSIVE":"1","WAYDROID_SELINUX_POLICY_DISCOVERY":"1"}}
]
}
1 change: 1 addition & 0 deletions conf/layer.conf
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@ BBFILES_DYNAMIC += " \
rust-bin-layer:${LAYERDIR}/bbappends/meta-rust-bin/*/*/*.bb rust-bin-layer:${LAYERDIR}/bbappends/meta-rust-bin/*/*/*.bbappend \
meta-tensorflow:${LAYERDIR}/bbappends/meta-tensorflow/*/*/*.bbappend \
nxp-zigbee-rcp:${LAYERDIR}/bbappends/meta-nxp-zigbee-rcp/*/*/*.bbappend \
selinux:${LAYERDIR}/dynamic-layers/selinux/recipes-*/*/*.bbappend \
"

LAYERDEPENDS_meta-dynamicdevices = "meta-lmp-base meta-dynamicdevices-bsp meta-dynamicdevices-distro"
Expand Down
45 changes: 45 additions & 0 deletions demos/jaguar-waydroid-gpu-demo/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# Jaguar Waydroid GPU demo

An offline OpenGL ES 2.0 starfield benchmark for the Jaguar Screen Waydroid
image. It displays the renderer reported by Android, live FPS, and particle
count. Tap the screen to cycle through 2,000, 10,000, 40,000, and 80,000
particles.

## Build

```sh
./build.sh
```

The build uses the latest Android SDK platform and build-tools installed under
`ANDROID_SDK_ROOT` or `~/Android/Sdk`. It compiles directly with the SDK
tools, so Gradle and network access are not required. The result is
`out/jaguar-gpu-demo.apk`, signed with the standard local Android debug key.

## Install on Jaguar Screen

Run the Waydroid commands as the same `weston` user that owns the graphical
session:

```sh
sudo -u weston env \
HOME=/var/rootdirs/home/weston \
XDG_RUNTIME_DIR=/run/user/63 \
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/63/bus \
WAYLAND_DISPLAY=wayland-1 \
waydroid app install /tmp/jaguar-gpu-demo.apk

sudo -u weston env \
HOME=/var/rootdirs/home/weston \
XDG_RUNTIME_DIR=/run/user/63 \
DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/63/bus \
WAYLAND_DISPLAY=wayland-1 \
waydroid app launch com.dynamicdevices.jaguargpu
```

The v1.0.0 bench baseline rendered 10,000 particles at approximately 13 fps at
the panel's full 1920x1200 logical resolution. The overlay identified
`Vivante GC600 rev 4653` and `OpenGL ES 2.0`.

The APK uses only Android platform APIs and has no network permission or
external runtime dependency.
22 changes: 22 additions & 0 deletions demos/jaguar-waydroid-gpu-demo/app/src/main/AndroidManifest.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
<?xml version="1.0" encoding="utf-8"?>
<!-- SPDX-License-Identifier: GPL-3.0-only -->
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
package="com.dynamicdevices.jaguargpu">
<uses-feature android:glEsVersion="0x00020000" android:required="true" />
<application
android:theme="@android:style/Theme.Material.NoActionBar"
android:label="Jaguar GPU Drive"
android:allowBackup="false"
android:supportsRtl="true">
<activity
android:name=".MainActivity"
android:screenOrientation="landscape"
android:configChanges="orientation|screenSize"
android:exported="true">
<intent-filter>
<action android:name="android.intent.action.MAIN" />
<category android:name="android.intent.category.LAUNCHER" />
</intent-filter>
</activity>
</application>
</manifest>
Loading
Loading