Files
bfe-core1106-sdk/build/fetch-buildroot-tarball.sh
T
NoahandClaude Opus 5 3d8a683d68 Pin where buildroot comes from
The firmware builds against sysdrv/source/buildroot/buildroot-2025.02.8 in the
vendor SDK. That tree is not in the vendor checkout -- the SDK ships 2023.02.6 --
it was not in this manifest, and nothing anywhere recorded its origin. A clean
rebuild on another machine silently fell back to the vendor's older buildroot
and produced a different userspace, which is flare-edge#135.

fetch-buildroot-tarball.sh follows fetch-kernel-tarball.sh exactly: pinned URL,
pinned sha256, fails closed on a missing pin. Buildroot signs releases with GPG
rather than publishing a .sha256, so the pin was computed from the tarball and
is what the script verifies against.

The manifest now says out loud that two of the inputs are tarballs rather than
git trees, so "which buildroot" has an answer in the same place as "which LVGL".

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T2D2KtdgwbhbF6Mo64eUrn
2026-09-03 21:24:10 -06:00

55 lines
1.8 KiB
Bash
Executable File

#!/usr/bin/env bash
# Fetch (with retries) and sha256-verify the pristine Buildroot tarball into $1.
#
# WHY THIS EXISTS. The firmware builds against
# sysdrv/source/buildroot/buildroot-2025.02.8 inside the vendor SDK. That tree
# is NOT in the vendor checkout -- the SDK ships 2023.02.6 -- and nothing
# recorded where it came from, so the build was reproducible only on the one
# machine that happened to have the directory (flare-edge#135). Buildroot signs
# its releases with GPG rather than publishing a .sha256, so the pin here was
# computed from the downloaded tarball and is what this script verifies against.
#
# Same shape as fetch-kernel-tarball.sh, deliberately: a version bump edits this
# file and the pin beside it, nothing else. FAILS CLOSED on a missing pin.
#
# Usage: fetch-buildroot-tarball.sh <destination-path>
set -euo pipefail
BRVER=2025.02.8
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" # build/
SHA_FILE="$HERE/buildroot-$BRVER.tar.xz.sha256"
URL="https://buildroot.org/downloads/buildroot-$BRVER.tar.xz"
TB="${1:?usage: fetch-buildroot-tarball.sh <destination-path>}"
[ -f "$SHA_FILE" ] || {
echo "FATAL: no pinned sha256 for buildroot-$BRVER (expected $SHA_FILE):" >&2
echo " refusing an unverified tarball" >&2
exit 1
}
WANT="$(awk '{print $1; exit}' "$SHA_FILE")"
verify() {
[ -f "$TB" ] || return 1
local got
got="$(sha256sum "$TB" | awk '{print $1}')"
[ "$got" = "$WANT" ]
}
if verify; then
echo "buildroot-$BRVER: already present and verified"
exit 0
fi
for attempt in 1 2 3; do
echo "== fetching buildroot-$BRVER (attempt $attempt)"
if curl -fsSL --retry 2 -o "$TB" "$URL" && verify; then
echo "buildroot-$BRVER: sha256 verified"
exit 0
fi
rm -f "$TB"
done
echo "FATAL: could not fetch a buildroot-$BRVER tarball matching $WANT" >&2
exit 1