From 958ddb5d5adb40efb546babfdea66f5d9510e28f Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Fri, 14 Aug 2026 16:42:30 +0530 Subject: [PATCH 1/5] Add syft/cyclonedx-cli as linux-pkg packages PR URL: https://www.github.com/delphix/linux-pkg/pull/414 --- package-lists/build/main.pkgs | 7 +++++++ packages/cyclonedx-cli/config.sh | 29 +++++++++++++++++++++++++++++ packages/syft/config.sh | 29 +++++++++++++++++++++++++++++ 3 files changed, 65 insertions(+) create mode 100755 packages/cyclonedx-cli/config.sh create mode 100755 packages/syft/config.sh diff --git a/package-lists/build/main.pkgs b/package-lists/build/main.pkgs index 429b5c7..af386e2 100644 --- a/package-lists/build/main.pkgs +++ b/package-lists/build/main.pkgs @@ -7,6 +7,11 @@ challenge-response cloud-init crash-python crypt-blowfish +# cyclonedx-cli and syft (below) are build-host-only tooling for appliance-build's +# CycloneDX SBOM generation (CP-13464/CP-13600) -- like delphix-go, they must never +# be referenced by any appliance-build chroot package list, so they never ship +# inside the appliance image despite being listed here. +cyclonedx-cli delphix-go delphix-platform delphix-rust @@ -28,6 +33,8 @@ ptools python-rtslib-fb savedump sdb +# see the cyclonedx-cli comment above -- same build-host-only rule applies here. +syft targetcli-fb virtualization windows-connector diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh new file mode 100755 index 0000000..64ac6e9 --- /dev/null +++ b/packages/cyclonedx-cli/config.sh @@ -0,0 +1,29 @@ +#!/usr/bin/env bash +# +# Copyright 2026 Delphix +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# shellcheck disable=SC2034 + +# +# TODO(CP-13600): points at a personal dev repo while this is prototyped -- +# the author has no delphix/ org repo-creation rights. Swap to +# https://github.com/delphix/delphix-cyclonedx-cli.git once that repo exists. +# +DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-cyclonedx-cli.git" + +function build() { + logmust mkdir -p "$WORKDIR/repo" + logmust dpkg_buildpackage_default +} diff --git a/packages/syft/config.sh b/packages/syft/config.sh new file mode 100755 index 0000000..ea3ec9d --- /dev/null +++ b/packages/syft/config.sh @@ -0,0 +1,29 @@ +#!/usr/bin/env bash +# +# Copyright 2026 Delphix +# +# Licensed under the Apache License, Version 2.0 (the "License"); +# you may not use this file except in compliance with the License. +# You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# shellcheck disable=SC2034 + +# +# TODO(CP-13600): points at a personal dev repo while this is prototyped -- +# the author has no delphix/ org repo-creation rights. Swap to +# https://github.com/delphix/delphix-syft.git once that repo exists. +# +DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-syft.git" + +function build() { + logmust mkdir -p "$WORKDIR/repo" + logmust dpkg_buildpackage_default +} From e1844b19db1442d24f5eb2ef94f729804461d8c8 Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Mon, 24 Aug 2026 12:54:00 +0530 Subject: [PATCH 2/5] Changed the syft and cyclonedx-cli repose from personal to delphix space. --- packages/cyclonedx-cli/config.sh | 7 +------ packages/syft/config.sh | 7 +------ 2 files changed, 2 insertions(+), 12 deletions(-) diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh index 64ac6e9..63c5d97 100755 --- a/packages/cyclonedx-cli/config.sh +++ b/packages/cyclonedx-cli/config.sh @@ -16,12 +16,7 @@ # # shellcheck disable=SC2034 -# -# TODO(CP-13600): points at a personal dev repo while this is prototyped -- -# the author has no delphix/ org repo-creation rights. Swap to -# https://github.com/delphix/delphix-cyclonedx-cli.git once that repo exists. -# -DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-cyclonedx-cli.git" +DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/cyclonedx-cli.git" function build() { logmust mkdir -p "$WORKDIR/repo" diff --git a/packages/syft/config.sh b/packages/syft/config.sh index ea3ec9d..7787c55 100755 --- a/packages/syft/config.sh +++ b/packages/syft/config.sh @@ -16,12 +16,7 @@ # # shellcheck disable=SC2034 -# -# TODO(CP-13600): points at a personal dev repo while this is prototyped -- -# the author has no delphix/ org repo-creation rights. Swap to -# https://github.com/delphix/delphix-syft.git once that repo exists. -# -DEFAULT_PACKAGE_GIT_URL="https://github.com/justsanjeev/delphix-syft.git" +DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/syft.git" function build() { logmust mkdir -p "$WORKDIR/repo" From 0caf2128ecf7076db4ae87e97560089ed662eded Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Mon, 24 Aug 2026 22:21:46 +0530 Subject: [PATCH 3/5] removing comments those are not very necessary. --- package-lists/build/main.pkgs | 4 ---- 1 file changed, 4 deletions(-) diff --git a/package-lists/build/main.pkgs b/package-lists/build/main.pkgs index af386e2..1fa2a34 100644 --- a/package-lists/build/main.pkgs +++ b/package-lists/build/main.pkgs @@ -7,10 +7,6 @@ challenge-response cloud-init crash-python crypt-blowfish -# cyclonedx-cli and syft (below) are build-host-only tooling for appliance-build's -# CycloneDX SBOM generation (CP-13464/CP-13600) -- like delphix-go, they must never -# be referenced by any appliance-build chroot package list, so they never ship -# inside the appliance image despite being listed here. cyclonedx-cli delphix-go delphix-platform From 6dfef7369b839e1c1f1c0d01bb2160dd652c76fa Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Tue, 25 Aug 2026 16:49:04 +0530 Subject: [PATCH 4/5] DLPX-98654 [linux-pkg] Set delphix-syft's PACKAGE_VERSION from SYFT_VERSION Without this, set_changelog() has no PACKAGE_VERSION to read and defaults the built package to 1.0.0 regardless of which Syft version is actually pinned in the syft repo's debian/rules -- notably poor provenance for an SBOM tool specifically. syft's debian/rules now exposes the pinned version via a SYFT_VERSION file (single source of truth, delphix-rust/RUSTC_VERSION pattern). Read that same file here to set PACKAGE_VERSION before dpkg_buildpackage_default runs, so "dpkg -l delphix-syft" on a build host can tell you which Syft produced a given CycloneDX SBOM. --- packages/syft/config.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/packages/syft/config.sh b/packages/syft/config.sh index 7787c55..9ba72f8 100755 --- a/packages/syft/config.sh +++ b/packages/syft/config.sh @@ -20,5 +20,15 @@ DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/syft.git" function build() { logmust mkdir -p "$WORKDIR/repo" + + # + # Instead of relying on linux-pkg to assign a default version like 1.0.0, set the + # version of the delphix-syft package to the pinned Syft version. This is done so + # that "dpkg -l delphix-syft" on a build host can tell you which Syft actually + # produced a given CycloneDX SBOM. + # + PACKAGE_VERSION="$(tr -d '\n' <"$WORKDIR/repo/SYFT_VERSION")" + [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" + logmust dpkg_buildpackage_default } From 7dc8ad8e60a00af7cee422789699fe8f14d3ef76 Mon Sep 17 00:00:00 2001 From: Sanjeev Rohila Date: Tue, 25 Aug 2026 17:09:41 +0530 Subject: [PATCH 5/5] DLPX-98654 [linux-pkg] Set delphix-cyclonedx-cli's PACKAGE_VERSION from CYCLONEDX_VERSION Same fix as the syft package: without this, set_changelog() has no PACKAGE_VERSION to read and defaults the built package to 1.0.0 regardless of which cyclonedx-cli version is actually pinned in the cyclonedx-cli repo's debian/rules. cyclonedx-cli's debian/rules now exposes the pinned version via a CYCLONEDX_VERSION file (single source of truth, delphix-rust/ RUSTC_VERSION pattern). Read that same file here to set PACKAGE_VERSION before dpkg_buildpackage_default runs, so "apt-cache policy delphix-cyclonedx-cli" on a build host can tell you which cyclonedx-cli validated a given CycloneDX SBOM. --- packages/cyclonedx-cli/config.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/packages/cyclonedx-cli/config.sh b/packages/cyclonedx-cli/config.sh index 63c5d97..d081b53 100755 --- a/packages/cyclonedx-cli/config.sh +++ b/packages/cyclonedx-cli/config.sh @@ -20,5 +20,15 @@ DEFAULT_PACKAGE_GIT_URL="https://github.com/delphix/cyclonedx-cli.git" function build() { logmust mkdir -p "$WORKDIR/repo" + + # + # Instead of relying on linux-pkg to assign a default version like 1.0.0, set the + # version of the delphix-cyclonedx-cli package to the pinned cyclonedx-cli version. + # This is done so that "apt-cache policy delphix-cyclonedx-cli" on a build host can + # tell you which cyclonedx-cli actually validated a given CycloneDX SBOM. + # + PACKAGE_VERSION="$(tr -d '\n' <"$WORKDIR/repo/CYCLONEDX_VERSION")" + [[ -n "$PACKAGE_VERSION" ]] || die "Failed to retrieve package version" + logmust dpkg_buildpackage_default }