summaryrefslogtreecommitdiffstats
path: root/recipes-devtools/python/python3-newrelic
diff options
context:
space:
mode:
authorBruce Ashfield <bruce.ashfield@gmail.com>2026-06-13 03:51:50 +0000
committerBruce Ashfield <bruce.ashfield@gmail.com>2026-06-13 03:51:50 +0000
commit96fd20b66e7a31b903f6a1545aef94b4739f8c28 (patch)
tree56c9ef0bd21d8ca57689b9c5ca33e785e4922ce8 /recipes-devtools/python/python3-newrelic
parent5ebb6ee6c1db9d77e029a13f84c75216acdbeee6 (diff)
downloadmeta-virtualization-96fd20b66e7a31b903f6a1545aef94b4739f8c28.tar.gz
container-bundle: add CONTAINER_FLAGS_ACCEPTED to acknowledge container licenses
container-bundle.bbclass emits a bb.warn on every parse of a recipe that fetches a remote container. The warning's intent is sound: the integrator is shipping content they did not build from source, and the license/redistribution implications deserve a deliberate review. After that review has happened, though, the warning has nowhere to go. It keeps firing on every build, and there is no way for an image recipe that intentionally bundles e.g. an alpine or busybox base container to have a clean parse log. Users who want to add deliberate third-party base images (the app-container-alpine demo Tim is working on is the immediate motivation) end up either editing the bbclass to suppress the warning entirely or living with the noise — both bad. Add CONTAINER_FLAGS_ACCEPTED, mirroring oe-core's LICENSE_FLAGS / LICENSE_FLAGS_ACCEPTED pattern. The recipe never declares its own container licenses as accepted; instead the integrator opts in via local.conf or distro config after reviewing each container: CONTAINER_FLAGS_ACCEPTED += "docker.io/library/alpine" URLs in CONTAINER_FLAGS_ACCEPTED are matched against both the full URL (with :tag or @digest) and the bare URL with tag/digest stripped, so accepting "docker.io/library/alpine" covers every tag of that container. A "*" wildcard accepts every third-party container — for distros that have a standing review process. When a URL matches, the bb.warn is demoted to a bb.note instead of being silenced entirely. The note remains in the build log and the recipe's task log, so SBOM tools, audit pipelines, and distro release reviews can still see that an acknowledged third-party container was pulled. The point of the change is to remove the visible "WARNING" line from clean builds, not to hide that the fetch happened. The unacknowledged-URL warning is also reworded to print a copy-pasteable CONTAINER_FLAGS_ACCEPTED line for the specific URL, so the user reading the warning doesn't have to grep the docs to find the variable name. Documentation lives in both the bbclass header block and docs/container-bundling.md (under a new "Acknowledging Third-Party Container Licenses" section), with the exact warning text and the exact note text quoted so they're greppable from either entry point. Signed-off-by: Bruce Ashfield <bruce.ashfield@gmail.com>
Diffstat (limited to 'recipes-devtools/python/python3-newrelic')
0 files changed, 0 insertions, 0 deletions