From 958ddb5d5adb40efb546babfdea66f5d9510e28f Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Fri, 14 Aug 2026 16:42:30 +0530 Subject: [PATCH 1/8] Add syft/cyclonedx-cli as linux-pkg packages PR URL: https://www.github.com/delphix/linux-pkg/pull/414 --- package-lists/build/main.pkgs | 7 +++++++ packages/cyclonedx-cli/config.sh | 29 +++++++++++++++++++++++++++++ packages/syft/config.sh | 29 +++++++++++++++++++++++++++++ 3 files changed, 65 insertions(+) create mode 100755 packages/cyclonedx-cli/config.sh create mode 100755 packages/syft/config.sh diff --git a/package-lists/build/main.pkgs b/package-lists/build/main.pkgs index 429b5c7..af386e2 100644 --- a/package-lists/build/main.pkgs +++ b/package-lists/build/main.pkgs @@ -7,6 +7,11 @@ challenge-response cloud-init crash-python crypt-blowfish +# cyclonedx-cli and syft (below) are build-host-only tooling for appliance-build's +# CycloneDX SBOM generation (CP-13464/CP-13600) -- like delphix-go, they must never +# be referenced by any appliance-build chroot package list, so they never ship +# inside the appliance image despite being listed here. +cyclonedx-cli delphix-go delphix-platform delphix-rust @@ -28,6 +33,8 @@ ptools python-rtslib-fb savedump sdb +# see the cyclonedx-cli comment above -- same build-host-only rule applies here. +syft targetcli-fb virtualization windows-connector diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh new file mode 100755 index 0000000..64ac6e9 --- /dev/null +++ b/packages/cyclonedx-cli/config.sh @@ -0,0 +1,29 @@ +#!/usr/bin/env bash +# +# Copyright 2026 Delphix +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# shellcheck disable=SC2034 + +# +# TODO(CP-13600): points at a personal dev repo while this is prototyped -- +# the author has no delphix/ org repo-creation rights. Swap to +# https://github.com/delphix/delphix-cyclonedx-cli.git once that repo exists. +# +DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-cyclonedx-cli.git" + +function build() { + logmust mkdir -p "$WORKDIR/repo" + logmust dpkg_buildpackage_default +} diff --git a/packages/syft/config.sh b/packages/syft/config.sh new file mode 100755 index 0000000..ea3ec9d --- /dev/null +++ b/packages/syft/config.sh @@ -0,0 +1,29 @@ +#!/usr/bin/env bash +# +# Copyright 2026 Delphix +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# shellcheck disable=SC2034 + +# +# TODO(CP-13600): points at a personal dev repo while this is prototyped -- +# the author has no delphix/ org repo-creation rights. Swap to +# https://github.com/delphix/delphix-syft.git once that repo exists. +# +DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-syft.git" + +function build() { + logmust mkdir -p "$WORKDIR/repo" + logmust dpkg_buildpackage_default +} From e1844b19db1442d24f5eb2ef94f729804461d8c8 Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Mon, 24 Aug 2026 12:54:00 +0530 Subject: [PATCH 2/8] Changed the syft and cyclonedx-cli repose from personal to delphix space. --- packages/cyclonedx-cli/config.sh | 7 +------ packages/syft/config.sh | 7 +------ 2 files changed, 2 insertions(+), 12 deletions(-) diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh index 64ac6e9..63c5d97 100755 --- a/packages/cyclonedx-cli/config.sh +++ b/packages/cyclonedx-cli/config.sh @@ -16,12 +16,7 @@ # # shellcheck disable=SC2034 -# -# TODO(CP-13600): points at a personal dev repo while this is prototyped -- -# the author has no delphix/ org repo-creation rights. Swap to -# https://github.com/delphix/delphix-cyclonedx-cli.git once that repo exists. -# -DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-cyclonedx-cli.git" +DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/cyclonedx-cli.git" function build() { logmust mkdir -p "$WORKDIR/repo" diff --git a/packages/syft/config.sh b/packages/syft/config.sh index ea3ec9d..7787c55 100755 --- a/packages/syft/config.sh +++ b/packages/syft/config.sh @@ -16,12 +16,7 @@ # # shellcheck disable=SC2034 -# -# TODO(CP-13600): points at a personal dev repo while this is prototyped -- -# the author has no delphix/ org repo-creation rights. Swap to -# https://github.com/delphix/delphix-syft.git once that repo exists. -# -DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-syft.git" +DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/syft.git" function build() { logmust mkdir -p "$WORKDIR/repo" From 0caf2128ecf7076db4ae87e97560089ed662eded Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Mon, 24 Aug 2026 22:21:46 +0530 Subject: [PATCH 3/8] removing comments those are not very necessary. --- package-lists/build/main.pkgs | 4 ---- 1 file changed, 4 deletions(-) diff --git a/package-lists/build/main.pkgs b/package-lists/build/main.pkgs index af386e2..1fa2a34 100644 --- a/package-lists/build/main.pkgs +++ b/package-lists/build/main.pkgs @@ -7,10 +7,6 @@ challenge-response cloud-init crash-python crypt-blowfish -# cyclonedx-cli and syft (below) are build-host-only tooling for appliance-build's -# CycloneDX SBOM generation (CP-13464/CP-13600) -- like delphix-go, they must never -# be referenced by any appliance-build chroot package list, so they never ship -# inside the appliance image despite being listed here. cyclonedx-cli delphix-go delphix-platform From 6dfef7369b839e1c1f1c0d01bb2160dd652c76fa Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Tue, 25 Aug 2026 16:49:04 +0530 Subject: [PATCH 4/8] DLPX-98654 [linux-pkg] Set delphix-syft's PACKAGE_VERSION from SYFT_VERSION Without this, set_changelog() has no PACKAGE_VERSION to read and defaults the built package to 1.0.0 regardless of which Syft version is actually pinned in the syft repo's debian/rules -- notably poor provenance for an SBOM tool specifically. syft's debian/rules now exposes the pinned version via a SYFT_VERSION file (single source of truth, delphix-rust/RUSTC_VERSION pattern). Read that same file here to set PACKAGE_VERSION before dpkg_buildpackage_default runs, so "dpkg -l delphix-syft" on a build host can tell you which Syft produced a given CycloneDX SBOM. --- packages/syft/config.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/packages/syft/config.sh b/packages/syft/config.sh index 7787c55..9ba72f8 100755 --- a/packages/syft/config.sh +++ b/packages/syft/config.sh @@ -20,5 +20,15 @@ DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/syft.git" function build() { logmust mkdir -p "$WORKDIR/repo" + + # + # Instead of relying on linux-pkg to assign a default version like 1.0.0, set the + # version of the delphix-syft package to the pinned Syft version. This is done so + # that "dpkg -l delphix-syft" on a build host can tell you which Syft actually + # produced a given CycloneDX SBOM. + # + PACKAGE_VERSION="$(tr -d '\n' <"$WORKDIR/repo/SYFT_VERSION")" + [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" + logmust dpkg_buildpackage_default } From 7dc8ad8e60a00af7cee422789699fe8f14d3ef76 Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Tue, 25 Aug 2026 17:09:41 +0530 Subject: [PATCH 5/8] DLPX-98654 [linux-pkg] Set delphix-cyclonedx-cli's PACKAGE_VERSION from CYCLONEDX_VERSION Same fix as the syft package: without this, set_changelog() has no PACKAGE_VERSION to read and defaults the built package to 1.0.0 regardless of which cyclonedx-cli version is actually pinned in the cyclonedx-cli repo's debian/rules. cyclonedx-cli's debian/rules now exposes the pinned version via a CYCLONEDX_VERSION file (single source of truth, delphix-rust/ RUSTC_VERSION pattern). Read that same file here to set PACKAGE_VERSION before dpkg_buildpackage_default runs, so "apt-cache policy delphix-cyclonedx-cli" on a build host can tell you which cyclonedx-cli validated a given CycloneDX SBOM. --- packages/cyclonedx-cli/config.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh index 63c5d97..d081b53 100755 --- a/packages/cyclonedx-cli/config.sh +++ b/packages/cyclonedx-cli/config.sh @@ -20,5 +20,15 @@ DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/cyclonedx-cli.git" function build() { logmust mkdir -p "$WORKDIR/repo" + + # + # Instead of relying on linux-pkg to assign a default version like 1.0.0, set the + # version of the delphix-cyclonedx-cli package to the pinned cyclonedx-cli version. + # This is done so that "apt-cache policy delphix-cyclonedx-cli" on a build host can + # tell you which cyclonedx-cli actually validated a given CycloneDX SBOM. + # + PACKAGE_VERSION="$(tr -d '\n' <"$WORKDIR/repo/CYCLONEDX_VERSION")" + [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" + logmust dpkg_buildpackage_default } From fbfbd9733679d37710b62a90789e73457b3e0419 Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Mon, 31 Aug 2026 12:27:48 +0530 Subject: [PATCH 6/8] Removing unnecessary comment --- package-lists/build/main.pkgs | 1 - 1 file changed, 1 deletion(-) diff --git a/package-lists/build/main.pkgs b/package-lists/build/main.pkgs index 1fa2a34..e9eb681 100644 --- a/package-lists/build/main.pkgs +++ b/package-lists/build/main.pkgs @@ -29,7 +29,6 @@ ptools python-rtslib-fb savedump sdb -# see the cyclonedx-cli comment above -- same build-host-only rule applies here. syft targetcli-fb virtualization From 3a1cdaab5c64a9fa5c4e2f6571e6340bc61097c0 Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Mon, 31 Aug 2026 18:24:41 +0530 Subject: [PATCH 7/8] DLPX-98654 [linux-pkg] Fix PACKAGE_VERSION extraction after SYFT_VERSION/CYCLONEDX_VERSION became two-line files syft and cyclonedx-cli's own PRs just folded the pinned checksum into the same SYFT_VERSION/CYCLONEDX_VERSION file as the version (line 1 version, line 2 checksum), for easier maintenance. This config.sh's "tr -d '\n' < FILE" read the whole file and stripped all newlines, so PACKAGE_VERSION would have become a garbled concatenation of the version and checksum (e.g. "1.46.0003f82f0...") instead of just "1.46.0" -- silently breaking the provenance fix from the previous commit. Use "sed -n '1p'" to take only the version line. --- packages/cyclonedx-cli/config.sh | 5 ++++- packages/syft/config.sh | 5 ++++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh index d081b53..27fcdb2 100755 --- a/packages/cyclonedx-cli/config.sh +++ b/packages/cyclonedx-cli/config.sh @@ -27,7 +27,10 @@ function build() { # This is done so that "apt-cache policy delphix-cyclonedx-cli" on a build host can # tell you which cyclonedx-cli actually validated a given CycloneDX SBOM. # - PACKAGE_VERSION="$(tr -d '\n' <"$WORKDIR/repo/CYCLONEDX_VERSION")" + # CYCLONEDX_VERSION holds the pinned version on line 1 and its checksum on line 2 + # (read by debian/rules) -- take only line 1 here, not the whole file. + # + PACKAGE_VERSION="$(sed -n '1p' "$WORKDIR/repo/CYCLONEDX_VERSION")" [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" logmust dpkg_buildpackage_default diff --git a/packages/syft/config.sh b/packages/syft/config.sh index 9ba72f8..829db80 100755 --- a/packages/syft/config.sh +++ b/packages/syft/config.sh @@ -27,7 +27,10 @@ function build() { # that "dpkg -l delphix-syft" on a build host can tell you which Syft actually # produced a given CycloneDX SBOM. # - PACKAGE_VERSION="$(tr -d '\n' <"$WORKDIR/repo/SYFT_VERSION")" + # SYFT_VERSION holds the pinned version on line 1 and its checksum on line 2 (read + # by debian/rules) -- take only line 1 here, not the whole file. + # + PACKAGE_VERSION="$(sed -n '1p' "$WORKDIR/repo/SYFT_VERSION")" [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" logmust dpkg_buildpackage_default From 3cb8c69cb7042383b2cc5cf9e8a2d8d405fd2971 Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Mon, 31 Aug 2026 18:33:17 +0530 Subject: [PATCH 8/8] DLPX-98654 [linux-pkg] Match SYFT_VERSION/CYCLONEDX_VERSION's new key=value format syft/cyclonedx-cli's own PRs switched their version+checksum pin files from positional lines to VERSION=/SHA256= key=value format for self-documentation. Update the PACKAGE_VERSION extraction here to match (grep '^VERSION=' | cut -d= -f2- instead of sed -n '1p'). --- packages/cyclonedx-cli/config.sh | 6 +++--- packages/syft/config.sh | 6 +++--- 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh index 27fcdb2..3ee3987 100755 --- a/packages/cyclonedx-cli/config.sh +++ b/packages/cyclonedx-cli/config.sh @@ -27,10 +27,10 @@ function build() { # This is done so that "apt-cache policy delphix-cyclonedx-cli" on a build host can # tell you which cyclonedx-cli actually validated a given CycloneDX SBOM. # - # CYCLONEDX_VERSION holds the pinned version on line 1 and its checksum on line 2 - # (read by debian/rules) -- take only line 1 here, not the whole file. + # CYCLONEDX_VERSION holds "VERSION=..." and "SHA256=..." lines (the latter also + # read by debian/rules) -- pull out just the version, not the whole file. # - PACKAGE_VERSION="$(sed -n '1p' "$WORKDIR/repo/CYCLONEDX_VERSION")" + PACKAGE_VERSION="$(grep '^VERSION=' "$WORKDIR/repo/CYCLONEDX_VERSION" | cut -d= -f2-)" [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" logmust dpkg_buildpackage_default diff --git a/packages/syft/config.sh b/packages/syft/config.sh index 829db80..987ee8f 100755 --- a/packages/syft/config.sh +++ b/packages/syft/config.sh @@ -27,10 +27,10 @@ function build() { # that "dpkg -l delphix-syft" on a build host can tell you which Syft actually # produced a given CycloneDX SBOM. # - # SYFT_VERSION holds the pinned version on line 1 and its checksum on line 2 (read - # by debian/rules) -- take only line 1 here, not the whole file. + # SYFT_VERSION holds "VERSION=..." and "SHA256=..." lines (the latter also read + # by debian/rules) -- pull out just the version, not the whole file. # - PACKAGE_VERSION="$(sed -n '1p' "$WORKDIR/repo/SYFT_VERSION")" + PACKAGE_VERSION="$(grep '^VERSION=' "$WORKDIR/repo/SYFT_VERSION" | cut -d= -f2-)" [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" logmust dpkg_buildpackage_default