From: ecordonnier@snap.com
To: openembedded-core@lists.openembedded.org
Cc: Etienne Cordonnier <ecordonnier@snap.com>
Subject: [OE-core][PATCH v2 1/2] package_manager/ipk: skip checksums for unsigned local feeds
Date: Thu, 30 Jul 2026 11:10:16 +0200 [thread overview]
Message-ID: <20260730091017.171702-1-ecordonnier@snap.com> (raw)
From: Etienne Cordonnier <ecordonnier@snap.com>
Computing checksums in the opkg Packages index requires reading every
.ipk file in full. For a large image with 7000+ packages (including
multi-gigabyte debug packages), this adds 150-300s to every do_rootfs run.
Checksums in the Packages index are only meaningful for signed feeds
(PACKAGE_FEED_SIGN=1): the GPG signature covers the Packages index
which contains the SHA256Sum of each .ipk, forming a chain of trust
that prevents tampered packages being swapped on a remote feed.
For unsigned local file:// feeds the packages are installed directly
from the build host filesystem where there is no tampering risk. Skip
all checksum generation in that case by passing no --checksum flags to
opkg-make-index (the tool's default behaviour when given no flags).
Pass --force-checksum to opkg so it does not error on the absent
checksum fields.
On a test image with 7000+ packages (including a 2.3 GB debug
package): write_index time reduced from ~180s to ~22s (8x speedup)
when opkg-make-index is configured to produce no checksums by default.
See https://git.openembedded.org/openembedded-core/commit/?id=e462f47489f35902b6972f9837d9adfa542fc796
("Enable sha256 checksums in opkg indexer", 2019) for the original rationale.
AI-Generated: Claude Sonnet 4.6
Signed-off-by: Etienne Cordonnier <ecordonnier@snap.com>
---
meta/lib/oe/package_manager/ipk/__init__.py | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/meta/lib/oe/package_manager/ipk/__init__.py b/meta/lib/oe/package_manager/ipk/__init__.py
index 344e0852177..93a12fad6a3 100644
--- a/meta/lib/oe/package_manager/ipk/__init__.py
+++ b/meta/lib/oe/package_manager/ipk/__init__.py
@@ -12,7 +12,7 @@ from oe.package_manager import *
from oe.package_manager.common_deb_ipk import OpkgDpkgPM
class OpkgIndexer(Indexer):
- def write_index(self):
+ def write_index(self, build_checksums=True):
arch_vars = ["ALL_MULTILIB_PACKAGE_ARCHS",
"SDK_PACKAGE_ARCHS",
]
@@ -44,8 +44,9 @@ class OpkgIndexer(Indexer):
if not os.path.exists(pkgs_file):
open(pkgs_file, "w").close()
- index_cmds.add('%s --checksum md5 --checksum sha256 -r %s -p %s -m %s %s' %
- (opkg_index_cmd, pkgs_file, pkgs_file, pkgs_dir, opkg_index_cmd_extra_params))
+ checksum_args = '--checksum md5 --checksum sha256 ' if build_checksums else ''
+ index_cmds.add('%s %s-r %s -p %s -m %s %s' %
+ (opkg_index_cmd, checksum_args, pkgs_file, pkgs_file, pkgs_dir, opkg_index_cmd_extra_params))
index_sign_files.add(pkgs_file)
@@ -103,8 +104,12 @@ class OpkgPM(OpkgDpkgPM):
self.deploy_dir = oe.path.join(self.d.getVar('WORKDIR'), ipk_repo_workdir)
self.deploy_lock_file = os.path.join(self.deploy_dir, "deploy.lock")
self.opkg_cmd = bb.utils.which(os.getenv('PATH'), "opkg")
+ self.from_feeds = (self.d.getVar('BUILD_IMAGES_FROM_FEEDS') or "") == "1"
+ self._build_checksums = self.from_feeds or self.d.getVar('PACKAGE_FEED_SIGN') == '1'
self.opkg_args = ['--volatile-cache', '-f', config_file, '-t', self.d.expand('${T}/ipktemp/'), '-o', target_rootfs]
self.opkg_args.extend(shlex.split(self.d.getVar("OPKG_ARGS")))
+ if not self._build_checksums:
+ self.opkg_args.append('--force-checksum')
if prepare_index:
create_packages_dir(self.d, self.deploy_dir, d.getVar("DEPLOY_DIR_IPK"), "package_write_ipk", filterbydependencies)
@@ -116,7 +121,6 @@ class OpkgPM(OpkgDpkgPM):
if not os.path.exists(self.d.expand('${T}/saved')):
bb.utils.mkdirhier(self.d.expand('${T}/saved'))
- self.from_feeds = (self.d.getVar('BUILD_IMAGES_FROM_FEEDS') or "") == "1"
if self.from_feeds:
self._create_custom_config()
else:
@@ -346,7 +350,7 @@ class OpkgPM(OpkgDpkgPM):
def write_index(self):
self.deploy_dir_lock()
- result = self.indexer.write_index()
+ result = self.indexer.write_index(build_checksums=self._build_checksums)
self.deploy_dir_unlock()
--
2.43.0
next reply other threads:[~2026-07-30 9:10 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 9:10 ecordonnier [this message]
2026-07-30 9:10 ` [OE-core][PATCH v2 2/2] opkg: enable sha256 checksum verification by default ecordonnier
2026-07-30 11:52 ` Paul Barker
2026-07-30 12:10 ` Etienne Cordonnier
2026-07-30 11:51 ` [OE-core][PATCH v2 1/2] package_manager/ipk: skip checksums for unsigned local feeds Paul Barker
2026-07-30 12:44 ` Etienne Cordonnier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730091017.171702-1-ecordonnier@snap.com \
--to=ecordonnier@snap.com \
--cc=openembedded-core@lists.openembedded.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.