Skip to content

commands/sbom: attach image ids to extension scopes (ENG-2199) - #290

Merged
lee-reinhardt merged 1 commit into
avocado-linux:mainfrom
hiagofranco:hfranco-eng-2199-image-ids
Sep 30, 2026
Merged

lee-reinhardt merged 1 commit into
avocado-linux:mainfrom
hiagofranco:hfranco-eng-2199-image-ids

Conversation

@hiagofranco

Copy link
Copy Markdown
Collaborator

Extension scopes carry the runtime manifest's image_id as an externalIdentifier and its sha256 as verifiedUsing; rootfs and initramfs carry os_build_id and initramfs_build_id. This is the join key the per-image fragments use. spdxIds are unchanged.

avocado sbom reads the manifests from the volume, connect upload passes the one it already has. A missing manifest only warns.

Split out of #285 as the first commit, unchanged. The --device command is parked on hfranco-eng-2199.

🤖 Generated with Claude Code

Extension scopes carry the runtime manifest's image_id as an
externalIdentifier and its sha256 as verifiedUsing; rootfs and
initramfs carry os_build_id and initramfs_build_id. This gives a
device-reported image set something to join against. spdxIds are
unchanged.

avocado sbom reads the manifests from the volume, connect upload passes
the one it already has. A missing manifest only warns.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@hiagofranco
hiagofranco force-pushed the hfranco-eng-2199-image-ids branch from 52bd964 to a635be3 Compare September 30, 2026 11:37
@lee-reinhardt
lee-reinhardt merged commit c9960d7 into avocado-linux:main Sep 30, 2026
7 checks passed
lee-reinhardt added a commit that referenced this pull request Oct 7, 2026
… header (#292)

## Summary

`avocado connect upload` now sends the runtime's SBOM to Connect the
same way it sends the images: one SBOM per uploaded image, PUT through a
presigned URL, instead of one document inline in the create-runtime
request. Connect can then store and index each image's packages once,
however many runtimes share that image.

- Each artifact in the create request may declare `sbom: { digest,
size_bytes }`. The server answers with an upload URL for every image it
has no indexed SBOM for, and the CLI PUTs those before the image parts,
so an image whose bytes are already stored can still be backfilled.
- `rootfs`, `initramfs` and the runtime's own sysroot go into the OS
bundle's SBOM; each extension's sysroot goes into that extension's. The
document namespace and package element ids derive from the image id, so
the same image uploaded from two runtimes indexes identically. Scope
element names still carry the uploading runtime
(`ext:<runtime>/<name>`); Connect keeps the first upload's document for
an image. Scope elements keep the image-id stamps from #290.
- A server that does not accept SBOMs is unaffected: it returns no URLs
and the upload proceeds as before, quietly. A failed SBOM PUT is a
warning, never an upload failure. An expired upload URL is refreshed
once.
- `avocado sbom` keeps one package element per rpm header instead of
collapsing elements that share a name, version and release. Two builds
of the same NEVRA in one image are now both listed, each with its own
header digest.

## User-visible changes

- New `avocado connect upload --no-sbom` to skip SBOM generation.
- `avocado connect runtimes list` gains an `SBOM` column (`indexed`,
`pending`, `failed`, `none`, or `?` against a server that does not
report it); `--output json` carries it as `sbom_state`.
- `--output json` on upload emits one `sbom_fragment` event per image
(`uploaded`, `skipped` or `failed`) and one `sbom_skipped` event, with a
reason, when the runtime's SBOM is not stored at all (`--no-sbom`,
`--file`, no packages, a failed scan, or a server that does not accept
SBOMs). An image Connect already indexed is reported per image as
`skipped` and is not a missing SBOM.
- Removed: `AVOCADO_UPLOAD_NO_SBOM=1`, replaced by `--no-sbom`.

The `avocado sbom` command surface is unchanged.

## Testing

- `cargo fmt --check`, `cargo clippy --all-targets --all-features -D
warnings` clean.
- `cargo test --no-fail-fast`: all integration test binaries pass. The
unit test binaries fail only the five tests that also fail on `main` on
macOS (`install_section_from_a_dropin_enables_the_unit` and four
`utils::stamps` tests that shell out to bash).
- End to end against a local Connect with the server side of this
contract: a real Jetson Orin Nano build uploaded four SBOMs (277, 140,
18 and 6 packages), each indexed with every package carrying its rpm
header digest and the scope elements carrying their image ids. A second
upload of the same build into another project PUT nothing and reported
all four images as already indexed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants