Files
bfe-core1106-sdk/build/vendor.manifest
T
NoahandClaude Opus 5 a367991998 Own the vendored trees by pinning them
LVGL and the vendor RV1106 SDK are what this platform is built against, and
nothing in this repo said WHICH ones. The two live outside every worktree as
shared checkouts, so "the version we build against" was whatever happened to be
on the machine.

They are pinned here now, by exact commit, with one script that obtains and
verifies them. Not copied: between them they are ~21 GB, the vendor SDK bakes
absolute paths into its host tools so it has to sit at one stable path anyway,
and a 21 GB git repo would be unusable while still not making anything
reproducible. What makes a build reproducible is knowing exactly which tree was
used, which is a commit id -- the same reasoning build/fetch-kernel-tarball.sh
already applies to the kernel, where a sha256 pin stands in for vendoring the
tarball.

Two behaviours worth stating, because both were wrong in the first draft:

- A checkout is detected by `.git` EXISTING, not by it being a directory. LVGL
  is checked out as a worktree here, where `.git` is a file.
- Local modifications are reported and are NOT a failure. The vendor SDK is
  supposed to carry them -- tools/build-firmware.sh applies our sdk-patches
  series into that tree on every build -- so a pristine checkout is the
  unusual state. Only a MISSING or DRIFTED tree fails.

Nothing is ever reset automatically: a tree off its pin is reported, because a
local change to a vendor tree is usually someone mid-debug, not something to
throw away on their behalf.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T2D2KtdgwbhbF6Mo64eUrn
2026-09-03 16:07:05 -06:00

20 lines
1.3 KiB
Plaintext

# Third-party trees this platform is built against, pinned to an exact commit.
#
# WHY A PIN AND NOT A COPY. Between them these are ~21 GB; the vendor SDK alone
# is 21 GB of build tree with absolute paths baked into its host tools. Copying
# that into git would make every clone of this repo unusable and would still not
# make the result reproducible. What makes a build reproducible is knowing
# EXACTLY which tree was used, and that is a commit id -- the same reasoning
# build/fetch-kernel-tarball.sh already applies to the kernel, where a sha256
# pin stands in for vendoring 150 MB of tarball.
#
# So this file is the single place that answers "which LVGL, which vendor SDK",
# and fetch-vendor.sh is the only thing that acts on it. A checkout that has
# drifted off its pin is reported, never silently used.
#
# Format: name<TAB>url<TAB>commit<TAB>description
# Blank lines and lines starting with '#' are ignored.
lvgl https://github.com/lvgl/lvgl.git 066d8db0b54819223357731f68961a90b3d785b4 LVGL v9.5.0-383-g066d8db0b: the UI toolkit warden-ui links against
luckfox-pico https://github.com/LuckfoxTECH/luckfox-pico.git 824b817f889c2cbff1d48fcdb18ab494a68f69d1 Vendor RV1106 SDK: buildroot userspace, U-Boot and the host packaging tools. Being replaced by this repo; still the source of the rootfs and the FIT/resource host tools.