public inbox for openembedded-core@lists.openembedded.org
 help / color / mirror / Atom feed
From: Hongxu Jia <hongxu.jia@windriver.com>
To: Richard Purdie <richard.purdie@linuxfoundation.org>,
	Jose Quaresma <quaresma.jose@gmail.com>
Cc: openembedded-core@lists.openembedded.org
Subject: Re: [OE-core] [PATCH] classes/yocto-check-layer: allow to explicitly skip check_network_flag in recipe
Date: Mon, 2 Mar 2026 10:15:33 +0800	[thread overview]
Message-ID: <989fa4ba-3165-4b44-b380-017e535d228f@windriver.com> (raw)
In-Reply-To: <c60d35e74e13c5d4c93eaac67dcb726c25e61f76.camel@linuxfoundation.org>

[-- Attachment #1: Type: text/plain, Size: 3428 bytes --]

On 2/28/26 18:50, Richard Purdie wrote:
> **
> *CAUTION: This email comes from a non Wind River email account!*
> Do not click links or open attachments unless you recognize the sender 
> and know the content is safe.
> On Sat, 2026-02-28 at 11:27 +0800, hongxu via lists.openembedded.org 
> <https://urldefense.com/v3/__http://lists.openembedded.org__;!!AjveYdw8EvQ!dv8OxyPCat01rw2zoB7PGs6RXntA8xaWqSRCY2_LQQIUia0jkGnmYKY3FxwT17lz3ILBlzW_b3fF2-zvT4HgUW0LVF-LshmGK-lhyg$> 
> wrote:
>> On 2/27/26 17:39, Jose Quaresma wrote:
>> hongxu via lists.openembedded.org 
>> <https://urldefense.com/v3/__http://lists.openembedded.org__;!!AjveYdw8EvQ!aBhDhydW4sVwHmPku-G3KfAkizU2zIqypxgoEenL-xjXJs5eoMzW0QXn8MVS7w9-QZvBeU26B0ju3x5wCHfoAWuj9pQ$> 
>> <hongxu.jia=windriver.com@lists.openembedded.org> escreveu (sexta, 
>> 27/02/2026 à(s) 07:21):
>>>>
>>>> +# Format: "BPN1:task1 BPN2:task2", separate by space
>>>> +# build-appliance-image uses pip at image time
>>>> +SKIP_CHECK_NETWORK_FLAG = "build-appliance-image:do_image"
>>>> +
>>>>  # Check that no tasks (with rare exceptions) between do_fetch and 
>>>> do_build
>>>>  # use the network.
>>>>  def check_network_flag(d):
>>>>      # BPN:task names that are allowed to reach the network, using 
>>>> fnmatch to compare.
>>>>      allowed = []
>>>> -    # build-appliance-image uses pip at image time
>>>> -    allowed += ["build-appliance-image:do_image"]
>>>> +    allowed += (d.getVar('SKIP_CHECK_NETWORK_FLAG') or '').split()
>>>>
>>>
>>> This could introduce severe reproducibility problems for someone who 
>>> claims to have a Yocto compatible layer.
>>>
>> The meta-tensorflow, who use bazel build system to build, it requires 
>> network access at do_compile if download mirror is not available.
>>
>> The bazel is similar bitbake, has fetch, configure, compile, but it 
>> combined as one command and invoked at bitbake's do_compile
>>
>> In order to support offline build, I've apply a local patch to bazel 
>> to save download tarball as download mirror [1]
>>
>> [1]https://git.yoctoproject.org/meta-tensorflow/commit/?id=88ca1af3768e5a01e6ba8b2f09d6cf2a0bfb621e
>>
>> If dowload mirror is available, the build will reuse it and network 
>> is not required, the reproducibility problems should be detected by 
>> binary comparison from two builds, we have oe-selftest case in 
>> oe-core by the way
>>
> If the fetching happens outside of do_fetch, it means meta-tensorflow 
> cannot be marked as Yocto Project Compatible.
>
> The point of the standard and this test is to move people towards 
> reproducbile builds with full manifests of the contents. If you bypass 
> the fetcher, we don't have any of these guarantees.
>
> Our plan was to work out a way to remove the fetching from 
> build-appliance too but we didn't want to hold off the implementation 
> of that on the rest of the standard. The fact we've not done that yet 
> is frustrating to me but it doesn't change what the intent of this 
> plan is. We don't want to add a way to bypass it unless there is 
> really good reason. Good reasons might be 'publishing tasks' where 
> we're writing data out to a remote, or we're running tests. I'd likely 
> suggests these be in specific well defined tasks similar to fetch with 
> known properties though.
>
Copy, understood

//Hongxu

> Cheers,
>
> Richard
>
>
>
>
>

[-- Attachment #2: Type: text/html, Size: 7661 bytes --]

      reply	other threads:[~2026-03-02  2:15 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-02-27  7:21 [PATCH] classes/yocto-check-layer: allow to explicitly skip check_network_flag in recipe Hongxu Jia
2026-02-27  9:39 ` [OE-core] " Jose Quaresma
2026-02-28  3:27   ` Hongxu Jia
2026-02-28 10:50     ` Richard Purdie
2026-03-02  2:15       ` Hongxu Jia [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=989fa4ba-3165-4b44-b380-017e535d228f@windriver.com \
    --to=hongxu.jia@windriver.com \
    --cc=openembedded-core@lists.openembedded.org \
    --cc=quaresma.jose@gmail.com \
    --cc=richard.purdie@linuxfoundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox