-
Notifications
You must be signed in to change notification settings - Fork 3
Nov 04, 2024 ‐ 16:00 UTC
Philipp Ahmann edited this page Nov 4, 2024
·
2 revisions
Host:
- Philipp Ahmann
Participants:
- Daniel Weingaertner
- Alfred Strauch
- Steven Carbno
- Gabriele Paoloni
- Nicole Pappler (joins 5:25)
Regrets:
- Kate Stewart
Attended Recently
-
Sebastian Hetze
-
Karen Bennet
-
Guy Lunardi
-
Andreas Bartelt
-
Thomas Mittelstädt
-
Stewart Hildebrand
-
Olivier Charrier
-
Walt Miner
- Previous meeting notes: https://github.com/elisa-tech/wg-systems/wiki/Sep-30,-2024-%E2%80%90-15:00-UTC
- AI-Philipp: Draw a picture which shows the interaction of all the initiatives currently around (CRA, Eclipse Automotive Process SIG, ELISA)
- AI-Philipp: Draw a picture illustrating the project proposal in a graphical way.
-
AI-Sebastian: Involvement of DIN can also be interesting. Sebastian will take a first contact.
- Contact initiated, but no response so far.
- AI: Invite the epam people to tell a bit about their work and planned activities.
- Text brought from gdoc to github wiki md file: https://github.com/elisa-tech/wg-systems/wiki/Software-Quality-Good-Practices-in-Open-Source-%E2%80%90-Proposal
- Linux Foundation Europe follow up Nov 12th
- Discuss with Eclipse SDV Process SIG on Nov 18th (positive response by Leonardo)
- Need to prepare and re-check material as preparation for the meetings.
- AGL, Zephyr, ELISA project representatives
- Bosch, Aisin, Panasonic, Toyota, Honda, Volvo from Automotive
- Few additional people in audience
- Discussion about AGL + ELISA future topics.
- VirtIO important.
- Follow-up on plumbers presentation for formal language specification
- What would "safe usage" of VirtIO mean. (E2E protection, communication methodology, Graphics sharing)
- Graphics is still unclear, but "Unified HMI" is a topic of interest for AGL members. https://github.com/unified-hmi
- VirtIO important.
- In case AGL members show more interest, this could mean sharing their use case and requirements.
- Remark: Currently there is a proposal on a middleware solution called Eclipse Safe Open Vehicle Core (SCORE).
- https://projects.eclipse.org/proposals/eclipse-safe-open-vehicle-core
- Build an image based on these components and AGL (yocto) to create a meaningful BOM for this.
- https://wiki.automotivelinux.org/agl-distro/release-notes
- AGL releases include an SBOM for the yocto part. What additional information is needed for a system perspective?
- Also AGL SBOM is just Yocto and does not include Xen, Zephyr, µC BOM or what ever else is part of the "system"
- AGL has no information on HBOM for the Hardware.
- OSS complying to "regulatory requirements" (kept vague explicitly)
- ELISA might be able to use GitHub server resources running on ARM
- ELISA Systems WG builds could be executed on ARM servers as a Qemu image
-
Initial idea to work on (implementation view):
- Bring the existing ZCU102 example into a generic ARM64 qemu image running on ARM server.
- Replace peta-Linux by AGL.
- Add stack elements from SCORE (eclipse-safe-open-vehicle-core) to promote SDV use case
- Have a boot test for the generated image running on the server.
- Generate an SBOM (Software) for the system elements Xen, Zephyr and Linux (yocto)
- Store SBOM results in a database
- Create same artifacts based on new Pull Requests.
- Consider how to treat the Hardware and have a HBOM part in the system composition
- How to track which hardware was used on the server being a virtual machine on a physical server.
- Initial idea to work on SPDX view to work on to create data:
-
We need to define what a "System" actually means!
- A system is a representation of included elements that are defined in other SBOMs. A computer system is defined as the integration of hardware, software, peripheral devices, data, and networking components. Together they perform computing tasks and facilitate user interaction. A system captures operational information such as relationships between the network, data, connections, and potentially operating systems ultimately enabling the performance of a wide range of tasks from basic computing to complex data analysis. The system is used to group components to define functionality or services. The grouping of services and functions impacts the definition and operation of a computing environment.
- What can get into a prototype system BOM (without being complete)
- Involve also the bootloader parts and the interfacing (ACPI vs. DTS) https://www.kernel.org/doc/html/v6.4-rc7/arm64/acpi_object_usage.html
- Hardware BOM:
- Virtual machines are considered as virtual hardware.
- What generated the virtual hardware and what is the virtual network driver.
-
https://www.cisa.gov/sites/default/files/2023-04/sbom-types-document-508c.pdf includes additional BOMs (maybe to early to have this as SPDX material for the database PoC)
- Build Supply Chain BOM is a different topic, and not for the initial scope
-
We need to define what a "System" actually means!
- System BOM + SPDX for Safety to get to agenda again in November (when 3.0 to be in yocto).
- Red Hat will present BASIL https://github.com/elisa-tech/basil at the Eclipse SDV at the TAC (Technical Advisory Committee) Tuesday 19th 12:00 UTC.
- (This week presentation is about Sphinx Needs by Useblocks)
- Dec 16, 2024
- Dec 02, 2024 - Eclipse SDV
- Nov 25, 2024
- Nov 18, 2024
- Nov 11, 2024
- Nov 04, 2024
- Oct 21, 2024
- Sep 30, 2024
- Sep 23, 2024
- Sep 02, 2024
- Aug 26, 2024
- Aug 12, 2024
- Aug 05, 2024
- Jul 08, 2024
- Jul 01, 2024
- Jun 24, 2024
- Jun 10, 2024
- May 27, 2024
- May 13, 2024
- Apr 29, 2024
- Apr 22, 2024 HBOM
- Apr 08, 2024
- Mar 18, 2024
- Mar 11, 2024
- Mar 04, 2024
- Feb 19, 2024
- Feb 12, 2024
- Jan 29, 2024
- Jan 22, 2024
- Jan 15, 2024
- Jan 08, 2024
2023 and earlier minutes
(still empty)