Repository navigation
commands/sbom: attach image ids to extension scopes (ENG-2199) - #290
Merged
lee-reinhardt merged 1 commit intoSep 30, 2026
Merged
Conversation
4 tasks done
Extension scopes carry the runtime manifest's image_id as an externalIdentifier and its sha256 as verifiedUsing; rootfs and initramfs carry os_build_id and initramfs_build_id. This gives a device-reported image set something to join against. spdxIds are unchanged. avocado sbom reads the manifests from the volume, connect upload passes the one it already has. A missing manifest only warns. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
hiagofranco
force-pushed
the
hfranco-eng-2199-image-ids
branch
from
September 30, 2026 11:37
52bd964 to
a635be3
Compare
lee-reinhardt
approved these changes
Sep 30, 2026
lee-reinhardt
added a commit
that referenced
this pull request
Oct 7, 2026
… header (#292) ## Summary `avocado connect upload` now sends the runtime's SBOM to Connect the same way it sends the images: one SBOM per uploaded image, PUT through a presigned URL, instead of one document inline in the create-runtime request. Connect can then store and index each image's packages once, however many runtimes share that image. - Each artifact in the create request may declare `sbom: { digest, size_bytes }`. The server answers with an upload URL for every image it has no indexed SBOM for, and the CLI PUTs those before the image parts, so an image whose bytes are already stored can still be backfilled. - `rootfs`, `initramfs` and the runtime's own sysroot go into the OS bundle's SBOM; each extension's sysroot goes into that extension's. The document namespace and package element ids derive from the image id, so the same image uploaded from two runtimes indexes identically. Scope element names still carry the uploading runtime (`ext:<runtime>/<name>`); Connect keeps the first upload's document for an image. Scope elements keep the image-id stamps from #290. - A server that does not accept SBOMs is unaffected: it returns no URLs and the upload proceeds as before, quietly. A failed SBOM PUT is a warning, never an upload failure. An expired upload URL is refreshed once. - `avocado sbom` keeps one package element per rpm header instead of collapsing elements that share a name, version and release. Two builds of the same NEVRA in one image are now both listed, each with its own header digest. ## User-visible changes - New `avocado connect upload --no-sbom` to skip SBOM generation. - `avocado connect runtimes list` gains an `SBOM` column (`indexed`, `pending`, `failed`, `none`, or `?` against a server that does not report it); `--output json` carries it as `sbom_state`. - `--output json` on upload emits one `sbom_fragment` event per image (`uploaded`, `skipped` or `failed`) and one `sbom_skipped` event, with a reason, when the runtime's SBOM is not stored at all (`--no-sbom`, `--file`, no packages, a failed scan, or a server that does not accept SBOMs). An image Connect already indexed is reported per image as `skipped` and is not a missing SBOM. - Removed: `AVOCADO_UPLOAD_NO_SBOM=1`, replaced by `--no-sbom`. The `avocado sbom` command surface is unchanged. ## Testing - `cargo fmt --check`, `cargo clippy --all-targets --all-features -D warnings` clean. - `cargo test --no-fail-fast`: all integration test binaries pass. The unit test binaries fail only the five tests that also fail on `main` on macOS (`install_section_from_a_dropin_enables_the_unit` and four `utils::stamps` tests that shell out to bash). - End to end against a local Connect with the server side of this contract: a real Jetson Orin Nano build uploaded four SBOMs (277, 140, 18 and 6 packages), each indexed with every package carrying its rpm header digest and the scope elements carrying their image ids. A second upload of the same build into another project PUT nothing and reported all four images as already indexed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Extension scopes carry the runtime manifest's
image_idas anexternalIdentifierand its sha256 asverifiedUsing;rootfsandinitramfscarryos_build_idandinitramfs_build_id. This is the join key the per-image fragments use.spdxIds are unchanged.avocado sbomreads the manifests from the volume,connect uploadpasses the one it already has. A missing manifest only warns.Split out of #285 as the first commit, unchanged. The
--devicecommand is parked onhfranco-eng-2199.🤖 Generated with Claude Code