Conversation
lxc meson fails with clang ThinLTO when the linker is ld.bfd; disable meson b_lto for lxc. Bump python3-gbinder to bullseye 1.1.2 (5089d76) for Cython 3 noexcept fixes required on Scarthgap/Python 3.12. Co-authored-by: Cursor <cursoragent@cursor.com>
Pin the focused LmP v96 backport that corrects stale patch context for the handheld and Phasora images. Assisted-by: Codex
Track Git's canonical renamed path in the exact baseline repair file set. Assisted-by: Codex
Keep the gate fail-closed for candidate-added warnings while avoiding false failures when shared sstate suppresses a pre-existing baseline warning. Assisted-by: Codex <codex@openai.com>
Run every protected tuple as an independent fail-fast-disabled matrix shard while preserving the single required Layer Adoption Gate aggregator. Keep the shared local driver full-matrix by default. Signed-off-by: Alex Lennon <ajlennon@dynamicdevices.co.uk> Assisted-by: Codex
Resolve protected Git LFS KAS inputs in the shared regression driver for both baseline and candidate worktrees, preserving identical local and CI preparation and failing closed if smudging does not occur. Signed-off-by: Alex Lennon <ajlennon@dynamicdevices.co.uk> Assisted-by: Codex
# Conflicts: # meta-dynamicdevices-bsp
Carry the per-ref Foundries variables through the layer-adoption overlay, preserve every bootstrap tuple immutably, and allow product BSP commits only when they contain the exact audited baseline repair. Signed-off-by: Alex Lennon <ajlennon@dynamicdevices.co.uk> Assisted-by: Codex
Refpolicy compiles policy text with native tools and BUILD_CC. Suppress its unused target compiler/libc defaults so exact preflight reaches and validates the Waydroid policy without building LLVM. Signed-off-by: Alex Lennon <ajlennon@dynamicdevices.co.uk> Assisted-by: Codex
Record the product-owner retirement and remove the corresponding image and mfgtool shards from the protected build matrix.\n\nAssisted-by: Codex <noreply@openai.com>
Run the current integration phase against the screen image and recovery tuple, while documenting that other active products remain deferred rather than deprecated.\n\nAssisted-by: Codex <noreply@openai.com>
Restrict the permissive domain to explicit development builds, add an enforcing smoke stack, record kernel and policy proof, and focus the current adoption phase on Jaguar Screen image and recovery coverage.\n\nAssisted-by: Codex <noreply@openai.com>
# Conflicts: # ci/layer-adoption-tuples.json # docs/PRODUCT_TUPLE_LIFECYCLE.md
Assisted-by: Codex <noreply@openai.com>
# Conflicts: # .github/actionlint.yaml # ci/layer-adoption-contract.json # ci/layer-adoption-tuples.json # docs/PRODUCT_TUPLE_LIFECYCLE.md # scripts/validation/capture-layer-state.sh # scripts/validation/detect-layer-adoption.py # scripts/validation/run-layer-adoption-regression.py # scripts/validation/tests/test_capture_layer_state.py # scripts/validation/tests/test_detect_layer_adoption.py # scripts/validation/tests/test_run_layer_adoption_regression.py
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Purpose
Add the R26 Jaguar Screen host foundation for running Waydroid with LmP SELinux enabled, while keeping the Android changes limited to container-awareness required by kernel-global SELinux.
Security and platform changes
selinuxonly for theandroid-container/explicit host-SELinux product contract;linux-lmp-fslc-imxSELinux kernel fragment;waydroid_tmodule and labels persistent/runtime/rootfs paths;waydroid_tto enforcing and rejects permissive policy outside an explicit local-development build;Focused R26 gate
Per product-owner direction, this phase runs only:
main-jaguar-screenAndroid-container image.imx8mm-jaguar-instand the Phasora families are explicitly deprecated. Other active products are deferred, not claimed as passed.Evidence
refpolicy-targeted:do_compile: 459/459 tasks passed from the exact checkout;waydroid.pp: 114,378 bytes, module enabled, nopermissive waydroid_tdeclaration;do_kernel_configcheck: 873/873 tasks passed in the candidate preflight;Remaining release gates
This PR enables the Foundries and hardware phase; it does not claim hardware acceptance. After merge, the exact manifest will be built in Foundries CI, deployed by OTA, and the development AVC evidence will be converted into narrow reviewed allow rules before the enforcing release capture and rollback evidence.