Skip to content

Buildroot configuration

AWTRIX NG keeps a Buildroot external tree in firmware/buildroot/. Buildroot builds a cross toolchain and a Linux userspace from source; an external tree adds project-specific packages and configuration without changing Buildroot itself. This tree cross-compiles awtrix-linux and its userspace dependencies for 32-bit ARM. Its cross toolchain is the one every program of a TC002 release is built with.

Do not run it by hand; the ARM system build runner prepares locked inputs and drives Buildroot.

What the output is

The output is a root filesystem tar archive, the cross toolchain in output/host/, and on request a relocatable SDK. There is no kernel image, device tree, bootloader, partition layout, installer or flash command, and the archive has no init system or startup service. It cannot boot a TC002 and is not TC002 firmware. The TC002 release is assembled separately (see AWTRIX NG on the TC002).

Contents

Path Role
external.desc, external.mk, Config.in Registers the tree as AWTRIX and includes its packages
configs/awtrix_armv7_defconfig The ARM profile
package/awtrix-ng/ Builds the shared Linux application from the runner's Git snapshot with CMake (host tests off) and installs the application, web UI and license notices
package/awtrix-base64/ densaugeo/base64 1.4.0, pinned by commit, installed to staging for the application build only
patches/linux-headers/6.18.52/ Archive and license hashes for the custom kernel header pin
scripts/post-build.sh Removes libstdc++ debugger helper scripts from the target

The configuration

The target is little-endian ARMv7 Cortex-A7 with NEON/VFPv4, hard-float ABI, musl and C++, the CPU of the TC002. Binaries built against this musl userspace cannot simply be mixed with glibc libraries or libraries built for another floating-point ABI.

OpenSSL and CA certificates support the application's outgoing TLS connections. Login, getty, SSH servers, BusyBox, an interactive shell and debugger packages are disabled. Kernel, U-Boot, Barebox and ARM Trusted Firmware are not built.

The application snapshot includes the project's own PubSubClient 2.8 source under lib/PubSubClient, with the shared inbound-packet bounds fixes. ESP32 and Linux use the same source; Buildroot does not select a second MQTT library. Its MIT notice ships with the application notices.

Buildroot 2025.02's kernel header menu stops at 6.12.x or later. Selecting that entry with the custom version 6.18.52 is intentional and follows its Kconfig help. These are userspace build headers only; BR2_LINUX_KERNEL stays disabled. BR2_DOWNLOAD_FORCE_CHECK_HASHES requires hashes for custom downloads too. Linux 6.18 changed the Free Software Foundation address in its GPL text, so its license hash differs from Buildroot's default header release; external.mk selects the complete version-specific hash file for this pin instead of mixing two conflicting hashes.

Pinned versions

The pins are recorded in tools/system/sources.lock.json:

Component Pin Notes
Buildroot 2025.02.18 Long-term support series, supported until March 2028
Linux userspace headers 6.18.52 Long-term kernel series
C/C++ compiler GCC 14.4.0 Selected by BR2_GCC_VERSION_14_X
C library musl 1.2.6 Version and patches from the pinned Buildroot
TLS library OpenSSL 3.5.8 Version and patches from the pinned Buildroot
Archive SHA-256
buildroot-2025.02.18.tar.xz e38ad1df6ea0479fff6419a87a64535d02131674d463be154a763ef725b55321
linux-6.18.52.tar.xz 2b69564f7d4fea0c859b1959ba33709ee6e9139bd100e30a853b57159a8221b8

The Buildroot checksum was computed from the official HTTPS archive; its detached signature is a separate provenance check and is not implied by the checksum. The Linux checksum comes from the official signed checksum manifest. The build verifies the pinned hashes; it does not set up a trusted PGP keyring for either project.

Pins are reviewed inputs, not a promise that a release has no known vulnerabilities. Updating a pin means refreshing the source lock, the hashes and the validation.

Build

From the repository root on Linux or WSL, with a new, dedicated directory on the Linux filesystem:

python3 tools/system/build.py doctor
python3 tools/system/build.py prepare --work "$HOME/awtrix-armv7-build" --revision HEAD
python3 tools/system/build.py configure --work "$HOME/awtrix-armv7-build"
python3 tools/system/build.py build --work "$HOME/awtrix-armv7-build" --jobs 4
python3 tools/system/build.py legal-info --work "$HOME/awtrix-armv7-build"

The runner owns the build inputs. Do not substitute an unrecorded working directory and claim the same source identity. The first build downloads the selected package sources.

At the Buildroot level, make source fills the download cache, make builds the userspace archive, make sdk packages the toolchain and make legal-info gathers license metadata and redistributable sources. After extracting the SDK to a new location, run its relocate-sdk.sh. The Buildroot manual describes external trees, SDK relocation, download caching and legal-info output.

Reproducibility

BR2_REPRODUCIBLE is on, but Buildroot calls it experimental and only promises identical output for the same absolute build and output paths. A real check needs two clean environments with the same pinned host tools, identical paths, source snapshot, configuration and SOURCE_DATE_EPOCH, with network access off during the builds. The reproduction runner does exactly this.

What a build does not show

An ARM ELF check or an emulated test validates the architecture and application behaviour. It does not show anything about TC002 boot, LEDs, audio, sensors, network, updates, recovery or power loss.

License evidence

Keep Buildroot's own source, this external tree, the exact application snapshot, the generated configuration, patches, source hashes and the legal-info output with each build record. Read legal-info/README: Buildroot reports missing material there, and its manifest is an aid, not a complete license audit.

The build includes GPL-licensed build tools, Linux userspace headers with the Linux syscall exception, MIT-licensed musl, GCC runtime libraries with their runtime exception, and Apache-2.0 OpenSSL. Package-specific license files and notices are authoritative. No proprietary TC002 firmware or vendor binary is included.

For components bundled inside the application itself, tools/system/components.json is the per-component decision record, checked by tools/system/check_components.py. The qualification tool builds a CycloneDX inventory and a hash-bound release report from Buildroot's show-info and legal-info. Both are described in ARM system build.