Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
75 commits
Select commit Hold shift + click to select a range
3f880a8
chore: adopt product feature architecture
ajlennon Sep 2, 2026
ea86322
chore: drop Improv from Jaguar screen
ajlennon Sep 2, 2026
ea75849
chore: pin explicit product software selection
ajlennon Sep 2, 2026
6897dc3
waydroid: validate required distro capabilities
ajlennon Sep 2, 2026
acb6347
chore: update product feature documentation
ajlennon Sep 2, 2026
172486f
feat(imx95): support canonical Android container build
ajlennon Sep 2, 2026
9ba96f9
bsp: provide i.MX development memtool
ajlennon Sep 2, 2026
b82b366
fix(android): require Vulkan capability
ajlennon Sep 2, 2026
fdbfbb4
feat(screen): stage isolated Qt 6.8 build config
ajlennon Sep 2, 2026
85f566a
distro: adopt provider-neutral display feature
ajlennon Sep 2, 2026
1f15370
distro: integrate explicit Jaguar screen stack
ajlennon Sep 2, 2026
4993786
bsp: integrate Jaguar screen hardware support
ajlennon Sep 2, 2026
f2383b4
bsp: complete Jaguar screen device-tree inputs
ajlennon Sep 2, 2026
1fc551b
kas: pin Godot runtime layer
ajlennon Sep 2, 2026
beeebf2
kas: pin Flutter runtime layer
ajlennon Sep 2, 2026
78a26e2
distro: migrate AESL onto canonical policy
ajlennon Sep 2, 2026
8e2e576
docs: use canonical distro in current configuration
ajlennon Sep 2, 2026
d8c70e6
docs: document final compatibility retirement gate
ajlennon Sep 2, 2026
854bcdd
distro: preserve effective product feature parity
ajlennon Sep 2, 2026
637a8ce
distro: retain Waydroid Vulkan compatibility
ajlennon Sep 2, 2026
ae52f40
docs: record product feature migration evidence
ajlennon Sep 2, 2026
cc67ca1
docs: record coordinated rollout candidates
ajlennon Sep 2, 2026
847be21
distro: preserve screen rotation in rollout candidate
ajlennon Sep 2, 2026
b9e6221
bsp: include proven imx95 boot chain
ajlennon Sep 2, 2026
de62d69
bsp: preserve disabled screen camera graph
ajlennon Sep 2, 2026
d1d2651
distro: retain Waydroid migration alias
ajlennon Sep 2, 2026
8f6ceae
docs: record manifest migration coverage
ajlennon Sep 2, 2026
d08ce97
feat(display): allow screenshots in dev images
ajlennon Sep 2, 2026
226a9b1
Merge branch 'feature/product-features-architecture' into feature/scr…
ajlennon Sep 2, 2026
83aa599
feat(screen): reconcile Qt prototype with product features
ajlennon Sep 2, 2026
ffbe791
feat(screen): restore branded boot and demo startup
ajlennon Sep 2, 2026
f53a759
bsp: correct Linux splash rotation
ajlennon Sep 2, 2026
f413b98
bsp: enable maintainable U-Boot screen profiles
ajlennon Sep 2, 2026
92f4191
fix(godot3): pin final libatomic link fix
ajlennon Sep 3, 2026
898f62c
Merge commit 'f413b98fb7acfbe3e4b641d4ac1720e5cc22aaa7' into feature/…
ajlennon Sep 3, 2026
139935c
build: pin reconciled Godot touch and atomic fixes
ajlennon Sep 3, 2026
cc512e3
screen: make Qt image proof reproducible
ajlennon Sep 3, 2026
7f2efe8
screen: consume Qt product feature
ajlennon Sep 4, 2026
79c750d
screen: keep Godot demos opt-in
ajlennon Sep 4, 2026
1af5896
kas: test Qt without injected graphics features
ajlennon Sep 4, 2026
e6ba155
feat(waydroid): provision Android images outside OSTree
ajlennon Sep 4, 2026
dc9b73c
docs: record Jaguar screen galcore rollback release
ajlennon Sep 4, 2026
2615af5
fix(waydroid): require Etnaviv on Jaguar screen
ajlennon Sep 4, 2026
0c49d6c
feat(android): wire Etnaviv graphics submodules
ajlennon Sep 4, 2026
ef6e16a
docs: record built galcore rollback target
ajlennon Sep 4, 2026
e81a5cb
fix(android): retain Etnaviv feature expansion
ajlennon Sep 4, 2026
c4424c7
docs: record authoritative rollback layer pins
ajlennon Sep 4, 2026
01ad181
fix(android): update Mesa Etnaviv provider policy
ajlennon Sep 4, 2026
f8e5ddc
feat(screen): add 2GB Waydroid memory controls
ajlennon Sep 7, 2026
1cddb28
feat(waydroid): pin Android 16 host runtime
ajlennon Sep 7, 2026
93e1217
feat(waydroid): pin Etnaviv runtime graphics
ajlennon Sep 7, 2026
f1eedf8
security(waydroid): restrict GPU device passthrough
ajlennon Sep 7, 2026
4c239a2
security(waydroid): allowlist V4L2 decoder nodes
ajlennon Sep 7, 2026
95548d5
test(waydroid): add acceleration evidence checks
ajlennon Sep 7, 2026
aad8bf5
build(screen): pin Waydroid DMA heap kernel support
ajlennon Sep 7, 2026
d679e99
feat(media): select NXP decoder by V4L2 capability
ajlennon Sep 7, 2026
7686aa0
build: pin stateful V4L2 decoder BSP
ajlennon Sep 7, 2026
0e37923
waydroid: supervise NXP V4L2 daemon
ajlennon Sep 7, 2026
24a30e5
waydroid: preserve configured preinstalled images
ajlennon Sep 7, 2026
95e4488
waydroid: require pinned Android 16 image evidence
ajlennon Sep 7, 2026
04c09f2
security: enforce Waydroid host device isolation
ajlennon Sep 7, 2026
99b1a84
test: record Waydroid board acceleration evidence
ajlennon Sep 7, 2026
5395da1
compliance: emit host SPDX and licence evidence
ajlennon Sep 7, 2026
cc28653
test(waydroid): harden release evidence gates
ajlennon Sep 9, 2026
a88603b
test(waydroid): prove acceleration gate rejects unsafe paths
ajlennon Sep 9, 2026
a9e4952
test(waydroid): measure CPU and storage headroom
ajlennon Sep 9, 2026
50fb7f9
test(waydroid): summarize frame-rate headroom
ajlennon Sep 9, 2026
7ee3ae6
build: gate host images on Android release provenance
ajlennon Sep 9, 2026
59f974e
compliance: install Android NOTICE licence evidence
ajlennon Sep 9, 2026
188a0ea
test(waydroid): accept tabbed restart status
ajlennon Sep 9, 2026
d00b718
test(waydroid): reject software GPU renderers
ajlennon Sep 9, 2026
9894ac3
waydroid: provide Android 16 metadata storage
ajlennon Sep 10, 2026
aee5aac
fix(waydroid): align host Binder runtime with Android 16
ajlennon Sep 11, 2026
65f6c43
ci: update Waydroid workflow actions
ajlennon Sep 14, 2026
c606a03
Merge main into Android 16 integration
ajlennon Sep 14, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
92 changes: 92 additions & 0 deletions .github/workflows/build-waydroid-imx8mm-aesl.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
name: Build AESL Android 16 Waydroid host image

on:
workflow_dispatch:
inputs:
android_artifact_dir:
description: Reviewed Android artifact root under /yocto/android-16-artifacts
required: true
type: string
release_mode:
description: Integration accepts userdebug; production requires production-gated Android user provenance
required: true
default: integration
type: choice
options:
- integration
- production

permissions:
contents: read

concurrency:
group: build-waydroid-imx8mm-aesl
cancel-in-progress: false

jobs:
build:
runs-on: [self-hosted, esl-proxmox]
timeout-minutes: 720
container:
image: dynamicdevices/yocto-ci-build@sha256:be170373625e77a6235a0bb3efb84d00be736221782d5d716e88aafd1b965794
options: --privileged --volume /yocto:/yocto
steps:
- uses: actions/checkout@v7
with:
submodules: recursive

- name: Validate Android evidence and CI storage
env:
AESL_ANDROID_ARTIFACT_DIR: ${{ inputs.android_artifact_dir }}
AESL_RELEASE_MODE: ${{ inputs.release_mode }}
run: |
case "${AESL_ANDROID_ARTIFACT_DIR}" in
/yocto/android-16-artifacts/*) ;;
*) echo "Android artifact must be under /yocto/android-16-artifacts" >&2; exit 1 ;;
esac
test -s "${AESL_ANDROID_ARTIFACT_DIR}/waydroid-images.inc"
test -s "${AESL_ANDROID_ARTIFACT_DIR}/source-manifest.xml"
test -s "${AESL_ANDROID_ARTIFACT_DIR}/build-info.json"
test -s "${AESL_ANDROID_ARTIFACT_DIR}/imx8mm/system.img"
test -s "${AESL_ANDROID_ARTIFACT_DIR}/imx8mm/vendor.img"
test -s "${AESL_ANDROID_ARTIFACT_DIR}/imx8mm/sbom.spdx.json"
if [ "${AESL_RELEASE_MODE}" = production ]; then
test -s "${AESL_ANDROID_ARTIFACT_DIR}/imx8mm/NOTICE-system.xml.gz"
test -s "${AESL_ANDROID_ARTIFACT_DIR}/imx8mm/NOTICE-vendor.xml.gz"
grep -Eq '^AESL_WAYDROID_SYSTEM_NOTICE_SHA256 = "[0-9a-f]{64}"$' \
"${AESL_ANDROID_ARTIFACT_DIR}/waydroid-images.inc"
grep -Eq '^AESL_WAYDROID_VENDOR_NOTICE_SHA256 = "[0-9a-f]{64}"$' \
"${AESL_ANDROID_ARTIFACT_DIR}/waydroid-images.inc"
fi
python3 scripts/validation/validate-waydroid-build-info.py \
"${AESL_ANDROID_ARTIFACT_DIR}/build-info.json" \
--release-mode "${AESL_RELEASE_MODE}"
(cd "${AESL_ANDROID_ARTIFACT_DIR}" && sha256sum --check --strict SHA256SUMS)
install -d /yocto/waydroid-host/kas-work /yocto/waydroid-host/kas-build
available_kib=$(df --output=avail /yocto | tail -1 | tr -d ' ')
minimum_kib=$((300 * 1024 * 1024))
test "${available_kib}" -ge "${minimum_kib}"
df -h / /yocto

- name: Build pinned i.MX8MM host image
env:
AESL_ANDROID_ARTIFACT_DIR: ${{ inputs.android_artifact_dir }}
AESL_YOCTO_WORK_ROOT: /yocto/waydroid-host
KAS_WORK_DIR: /yocto/waydroid-host/kas-work
KAS_BUILD_DIR: /yocto/waydroid-host/kas-build
run: kas build kas/waydroid-imx8mm-aesl.yml

- name: Verify deploy evidence
run: |
deploy=/yocto/waydroid-host/tmp/deploy/images/imx8mm-jaguar-screen
test -d "${deploy}"
find "${deploy}" -maxdepth 1 -type f -printf '%f\n' | sort
find "${deploy}" -maxdepth 1 -type f -name '*.manifest' -print -quit | grep -q .
find "${deploy}" -maxdepth 1 -type f -name '*.spdx.tar.zst' -print -quit | grep -q .

- uses: actions/upload-artifact@v7
with:
name: aesl-waydroid-imx8mm-host-${{ github.run_id }}-${{ github.run_attempt }}
path: /yocto/waydroid-host/tmp/deploy/images/imx8mm-jaguar-screen
if-no-files-found: error
retention-days: 30
2 changes: 1 addition & 1 deletion docs/CRA-Compliance-Guide.md
Original file line number Diff line number Diff line change
Expand Up @@ -125,7 +125,7 @@ Each audit event generates a comprehensive JSON report:
The CRA compliance system is built into the distro layer and automatically enabled:

```bash
# In meta-dynamicdevices-distro/conf/distro/lmp-dynamicdevices-headless.conf
# In meta-dynamicdevices-distro/conf/distro/lmp-dynamicdevices.conf
DISTRO_FEATURES:append = " cra-audit"
```

Expand Down
3 changes: 2 additions & 1 deletion docs/investigations/IMX93_SECURE_BOOT_REPORT.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,8 @@ refs/heads/main-imx93-jaguar-eink:
machines:
- imx93-jaguar-eink
params:
DISTRO: lmp-dynamicdevices-headless
DISTRO: lmp-dynamicdevices
DD_PRODUCT_FEATURES: "improv"
# Enable secure boot and image signing for production
UBOOT_SIGN_ENABLE: "1"
TF_A_SIGN_ENABLE: "1"
Expand Down
89 changes: 89 additions & 0 deletions docs/product-feature-migration-validation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,89 @@
# Product-feature migration validation

Validation date: 2026-09-02

This records local evidence for migration to the canonical
`lmp-dynamicdevices` distro. It is not approval to publish factory pins or to
retire compatibility distro files.

## Effective feature parity

| Product | Legacy selection | Canonical `DD_PRODUCT_FEATURES` | Result |
| --- | --- | --- | --- |
| Jaguar Sentai | `lmp-dynamicdevices-headless` | `improv` | Same effective `DISTRO_FEATURES` token set |
| Jaguar DT510 | `lmp-dynamicdevices-headless` | `improv usb-gadget` | Same effective token set; legacy comments mention ALSA but the effective configuration removes it |
| Jaguar Screen | legacy screen-enabled headless configuration | `display flutter godot` | Same effective display/UI/audio token set; deliberately no Improv |
| Android/Waydroid products | `lmp-dynamicdevices-headless-waydroid` | `android-container` | Preserves Wayland, OpenGL, PulseAudio and ALSA; adds Vulkan because the current Waydroid recipe requires it |

Headless operation was also checked with an empty feature selection. It omits
display, UI, audio-runtime, Android and Improv software features. Hardware
capabilities such as Bluetooth remain in `MACHINE_FEATURES` and do not select
product software.

## Compatibility checks

- Unknown product-feature names fail at `ConfigParsed`.
- `display`, `flutter` and `godot` fail unless the machine declares
`display-multimedia`.
- Selecting `display` on `imx8mm-jaguar-sentai` was verified to fail.
- Standalone `audio` was verified to expand to ALSA and PulseAudio.
- `imx8mm-jaguar-screen` declares `display-multimedia` in the BSP.

## Dependency proofs

- `imx8mm-jaguar-screen`, `display flutter godot`:
`bitbake -n lmp-factory-image` completed all 9,463 tasks successfully.
- `imx95-frdm-evk`, `android-container`:
`bitbake -n lmp-factory-image` completed all 7,722 tasks successfully.
- The Android check also proved that removing Vulkan makes `waydroid`
unbuildable because its recipe lists Vulkan in `REQUIRED_DISTRO_FEATURES`.

No prior rootfs package manifests were present in the local worktrees, so a
package-by-package manifest comparison is not claimed. Effective feature-set
comparison and complete dry-run dependency graphs are the available local
evidence.

## Rollout gates still required

Validated local rollout candidates (all worktrees clean when recorded):

| Repository/worktree | Commit |
| --- | --- |
| `meta-dynamicdevices-bsp` | `c1868e70e8e2` |
| `meta-dynamicdevices-distro` | `e8cbf0061fea` |
| `meta-dynamicdevices` superproject | `d1d2651ca14a` |
| Foundries `ci-scripts` | `53e954882c97` |
| AESL `factory-core-ci` | `33b25f2d8b6e` |
| AESL Factory Definition | `379727319ef4` |

Publish dependencies before their consumers: distro and BSP first,
superproject next, then Foundries/AESL configuration and manifest pins.

1. Publish the distro, BSP, superproject, Foundries Factory Definition and
AESL runner/config branches in dependency order.
2. Update public/private manifest pins to the published commits.
3. Build deployable images and retain their rootfs/package manifests as the new
baselines.
4. Boot and exercise the Screen and Android targets on hardware, including
display/touch, Flutter, Godot, Waydroid, audio where selected, OTA identity
and rollback-sensitive behavior.
5. Confirm no live factory, manifest or local build consumer names a legacy
distro; only then delete the compatibility distro files.

## Foundries manifest consumer audit

The Factory Definition references 19 branch names. Sixteen currently exist in
the Foundries manifest repository. Canonical-stack pin migrations are live for
`main-imx95-frdm-devel` and `main-jaguar-screen`; validated local rollout
commits are prepared for the other fourteen existing branches.

The following configured branch names do not exist in the manifest repository
and therefore cannot be migrated or built as named:

- `imx8mm-jaguar-handheld-5in`
- `imx8mm-jaguar-handheld-7in`
- `main-rpi5`

`main-jaguar-handheld` does exist, but it does not match either configured
handheld branch name. These stale/mismatched Factory Definition entries must be
resolved before the final no-legacy-consumer gate can pass.
50 changes: 50 additions & 0 deletions docs/releases/jaguar-screen-galcore-baseline-2026.09.04.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,50 @@
# Jaguar Screen galcore rollback baseline — 2026-09-04

This release preserves the last i.MX8MM Jaguar Screen configuration before the
Waydroid graphics stack is changed from NXP galcore/imx-gpu-viv to Mesa
Etnaviv.

## Release identity

- Release tag: `jaguar-screen-galcore-baseline-2026.09.04`
- Foundries factory: `dynamic-devices`
- Machine: `imx8mm-jaguar-screen`
- Hardware-lab device: `imx8mm-jaguar-screen-2210a09dab86563`
- Hardware rollback target: Foundries target `2838`
- Tagged source release build: Foundries target `2840`
- Target 2840 OSTree: `0008cdaca80b08c524d6db29df02c6c168382ea9e8de07814083380a04d36ea2`
- Manifest-pinned BSP: `6ca2f503c0310cb6605890f09b68158cf3b0cf22`
- Manifest-pinned distro: `84566da924d5f04ddaf1714b785ad6cd2625ef45`

The top-level repository also records Git submodule links, but Foundries repo
sync treats the explicit BSP and distro projects in `dynamic-devices.xml` as
authoritative. Use the manifest-pinned revisions above for reproduction.

The manifest and CI repositories carry the same release tag. Their tagged
revisions are the authoritative source assembly and build configuration.

## Known state

- The host display is operational through `imx-drm` with NXP's proprietary
`galcore`, `imx-gpu-viv`, EGL/GBM and Weston G2D renderer stack.
- Waydroid 1.4.2 and its Android 13 system/vendor images are installed on the
hardware target.
- Binder support and the Android container start correctly.
- Waydroid graphics do **not** boot to a usable Android UI in this release.
The generic Android vendor image uses Mesa Etnaviv, which cannot allocate
buffers through the host's galcore DRM device. SurfaceFlinger aborts with
`Failed to allocate buffer` / `output buffer not gpu writeable`.
- Android images are provisioned into `/var/lib/waydroid/images` rather than
included in the OSTree payload.

## Rollback

Prefer an OTA rollback of the hardware-lab device to Foundries target `2840`,
which was built from the tagged manifest commit. Target `2838` remains the
known-running pre-release hardware fallback.
For a source rollback, check out this tag in `meta-dynamicdevices`,
`lmp-manifest`, and `ci-scripts`, then build the tagged manifest without any
Etnaviv experiment commits.

Do not describe target 2838 as an Etnaviv or accelerated-Waydroid target: it is
the deliberately retained galcore baseline.
91 changes: 91 additions & 0 deletions docs/waydroid-android16-build.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
# AESL Android 16 Waydroid host build

The i.MX8MM product deliberately refuses to reuse the recipe's legacy
LineageOS 18.1 payload. Build the reviewed LineageOS 23.2 manifest first; its
artifact root contains raw `imx8mm/system.img`, `imx8mm/vendor.img`, the SPDX
JSON SBOM, immutable source manifest, build metadata, and a generated
`waydroid-images.inc` containing their exact hashes.

All persistent source trees, downloads, caches, build outputs, and large CI
artifacts must remain on the dedicated `/yocto` volume. On the self-hosted
runner, build the host image with:

```sh
AESL_ANDROID_ARTIFACT_DIR=/yocto/android-16-artifacts/RUN-ATTEMPT \
AESL_YOCTO_WORK_ROOT=/yocto/waydroid-host \
KAS_WORK_DIR=/yocto/waydroid-host/kas-work \
KAS_BUILD_DIR=/yocto/waydroid-host/kas-build \
kas build kas/waydroid-imx8mm-aesl.yml
```

The KAS profile rejects artifact and work paths outside `/yocto`; `waydroid-data`
rejects absent or malformed SHA-256 pins and installs the SBOM, source lock,
and build metadata as release evidence alongside the chunked images.
The proof profile also re-enables OpenEmbedded SPDX generation and copies the
host package licence manifest and licence texts into the image. CI fails unless
the deploy directory contains the host image manifest and SPDX archive, so the
Android SBOM is not mistaken for a complete product SBOM.

The host workflow defaults to `integration` mode so a reviewed Android
`userdebug` artifact can be exercised on the board. Select `production` only
with an Android `user` artifact whose `build-info.json` records both production
release class and the blocking SELinux production gate; the workflow rejects
missing or integration-only provenance. Production also requires the Android
system and vendor NOTICE archives. Their generated pins are consumed by
`waydroid-data` and the archives are installed beside the Android SBOM and
source-lock evidence.

CI runs this inside the digest-pinned Yocto build container with `/yocto`
mounted at the same absolute path. Do not substitute `kas-container` without
also arranging that mount and explicitly forwarding the AESL variables.

## Host container security gate

The `android-container` product feature also enables the AppArmor distro
feature. The Jaguar kernel builds AppArmor into its ordered LSM list, and the
Waydroid recipe installs all three upstream profiles in enforce mode. Image
provisioning waits for `apparmor.service`; if the `lxc-waydroid` profile is not
loaded, the generated LXC configuration remains unconfined and the runtime
verification must fail.

The patched, pinned Waydroid 1.6.3 runtime writes a deny-by-default LXC device
policy. It then grants `rwm` only to fixed pseudo devices and the exact major
and minor numbers of bind-mounted character devices. The product provisioner
separately limits mounts to the chosen Etnaviv render node, approved DMA heaps,
and the capability-selected NXP decoder. The GPU and heaps are `root:1003`
(`AID_GRAPHICS`) mode `0660`; the decoder is `root:1013` (`AID_MEDIA`) mode
`0660`. No block-device or wildcard device grant is generated.

On the target, run:

```sh
sudo /usr/libexec/waydroid-acceleration-check
```

This is a release gate: it checks AppArmor is enabled and enforcing, the LXC
profile is selected, the device policy is deny-by-default with exact rules,
and the Android GPU/Vulkan/Codec2 runtime state matches the product contract.

The Android 16 Binder contract is pinned independently of the Android images:
Waydroid 1.6.3 selects the AIDL6 service-manager protocol for API 36,
libgbinder 1.1.52 is fixed at
`e906afcffbfa51b7fbefe042a13b933d9e8dfdd9`, and libglibutil 1.0.82 is fixed
at `cccc4aa8f1745096f6feb66da7883b35055d9423`. The Waydroid recipe carries a
narrow compatibility patch which selects `id.waydro.waydroid.IPlatform` only
for AIDL6, retaining the legacy descriptor for older Android images.

Record the complete target snapshots and restart proof with:

```sh
sudo /usr/libexec/waydroid-board-evidence capture
sudo /usr/libexec/waydroid-board-evidence restart
```

Suspend/resume is a two-stage test so the evidence survives the SSH session
dropping during suspend:

```sh
sudo /usr/libexec/waydroid-board-evidence suspend-prepare /var/log/waydroid-validation/suspend-1
# Suspend and wake the board using the product wake source.
sudo /usr/libexec/waydroid-board-evidence suspend-verify /var/log/waydroid-validation/suspend-1
```
37 changes: 37 additions & 0 deletions docs/waydroid-imx8mm-2gb-memory.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
# Waydroid memory profile for i.MX8MM 2 GB

The `imx8mm-jaguar-screen` Waydroid image enables a 768 MiB LZ4 zram swap
device before the container starts. The container has a provisional
`MemoryHigh` of 1200 MiB and `MemoryMax` of 1500 MiB.

These values are starting controls, not proof of capacity. On the shipping
image, run:

```sh
/usr/libexec/waydroid-memory-headroom
```

Collect results at idle, after kiosk launch, during video playback, during an
application update and after repeated application restarts. The report takes a
two-second CPU sample and records the host filesystems that contain Waydroid's
state and images. Also check the kernel journal for OOM kills and zram
writeback failures.

`waydroid-board-evidence capture` also records raw SurfaceFlinger presentation
timestamps and summarizes the target refresh rate, effective frame rate,
missed refresh intervals and worst frame gap. Capture this during steady-state
shipping kiosk animation and video playback; an idle surface is not a valid
frame-rate headroom measurement.

Resource gates under the target workload:

- green: container peak below 70% of `MemoryMax` and host available memory
above 30%, CPU busy below 70% with idle above 30%, and relevant filesystems
below 70%;
- amber: RAM or filesystem use reaches 70%, CPU busy reaches 70%, or CPU idle
falls to 30%;
- red: RAM or filesystem use reaches 85%, CPU busy reaches 85%, CPU idle falls
to 15%, `memory.events` reports `oom`/`oom_kill`, or the kernel OOM killer
runs.

Adjust `MemoryHigh`, `MemoryMax` or zram size only from recorded board data.
10 changes: 10 additions & 0 deletions kas/base.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,6 +66,16 @@ repos:
commit: eeee54cfa3c51c1fd99604a0d5f173096bdcf1da
path: build/layers/meta-tensorflow

meta-godot:
url: https://github.com/active-esl/meta-godot.git
commit: 5396659eed1cb6a0192a9928a35c8fc57f57d1c8
path: build/layers/meta-godot

meta-flutter:
url: https://github.com/meta-flutter/meta-flutter.git
commit: 34a3d4eb3a36b8c9c2af9c4ef2b75986d821fa3f
path: build/layers/meta-flutter

openembedded-core:
url: https://github.com/lmp-mirrors/openembedded-core
commit: 7a59dc5ee6edd9596e87c2fbcd1f2594c06b3d1b
Expand Down
Loading
Loading