ci(ifx_package_core): pre-install imgtool signing deps for kit_pse84_ai - #24
Merged
Merged
Conversation
IFX-Anusha
requested review from
AkshayChandra-IFX,
djaumann and
jaenrig-ifx
September 23, 2026 12:43
IFX-Anusha
marked this pull request as draft
September 23, 2026 12:50
hal_infineon's pse84_metadata.cmake attempts to pip-install imgtool's Python dependencies (cryptography, cbor2, click, intelhex, Pillow) at CMake-configure time, but only emits a message(WARNING ...) if that fails rather than aborting the build. In our CI this silently no-ops, and the failure resurfaces later as a confusing ModuleNotFoundError: No module named 'cryptography' from imgtool.py during the post-build signing step. Pre-install the same packages explicitly in this workflow, scoped to kit_pse84_ai only, so the existing HAL-level install attempt becomes a harmless no-op regardless of whether/why it fails in CI.
IFX-Anusha
force-pushed
the
ifx-pse84-imgtool-deps
branch
from
September 23, 2026 12:56
f598be1 to
c0ff9f7
Compare
IFX-Anusha
marked this pull request as ready for review
September 23, 2026 12:57
jaenrig-ifx
approved these changes
Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
By creating this pull request you agree to the terms in CONTRIBUTING.md.
https://github.com/Infineon/.github/blob/master/CONTRIBUTING.md
--- DO NOT DELETE ANYTHING ABOVE THIS LINE ---
CONTRIBUTING.md also tells you what to expect in the PR process.
Description
Problem
kit_pse84_ai's build fails at the final imgtool-signing post-build stepwith
ModuleNotFoundError: No module named 'cryptography'.History: how this was handled before the branch split
On
pre-branch-split-main, this exact problem was solved with a Zephyrsource patch (
0002-soc-infineon-pse84-install-imgtool-python-deps.patch,applied via
apply_zephyr_patches.sh) that added a pip-installexecute_process()block directly into hal_infineon'spse84_metadata.cmake, so the dependencies got installed at CMakeconfigure time.
That patch mechanism isn't available on this branch structure by design
(patches touch Zephyr/HAL source under
west-managed modules, which weintentionally avoid modifying in-tree to keep sync/rebase simple). We
also confirmed via a debug CI run that the version of
pse84_metadata.cmakeactually pinned by this branch's
west.ymlmanifest doesn't contain anypip-install logic at all yet — so the old patch's approach isn't currently
applicable here regardless.
This fix
Pre-install the same 5 packages (
cryptography,cbor2,click,intelhex,Pillow) as an explicit workflow step, scoped tokit_pse84_aionly, right before the board build runs. This isdeliberately NOT a patch and NOT a change to
bootstrap.sh(which wouldinstall these unconditionally for every board, forever) — it's the
smallest, most scoped fix: one board, one workflow, no shared-file/HAL
changes, zero rebase-risk.
This is a temporary workaround, not the real fix
The correct long-term fix belongs upstream, in one of:
pse84_metadata.cmakeitself reliably installing its ownimgtool dependencies at CMake-configure time (it already attempts this
in newer HAL revisions, but only via
message(WARNING ...)on failure,which lets the build proceed and fail later with a confusing error
instead of aborting cleanly).
cryptography,cbor2, etc.)being installed as part of Zephyr's own standard workspace bootstrap
(
requirements-base.txt), the same way every other Zephyr board thatsigns images with imgtool is expected to have
pip3 install imgtoolrun manually beforehand — this is literally called out as a TODO in the
current
pse84_metadata.cmakesource: "Remove once mcuboot's Pythonrequirements are installed as part of the standard Zephyr workspace
setup."
Until either of those lands upstream in the HAL/Zephyr modules we
consume, this workflow-level pre-install keeps our CI green without
depending on unreliable, warning-only auto-install logic living in a
module we don't control.