libcamera: ipa_manager: Allow forcing IPA module isolation

For test purpose it's useful to run open-source IPA modules in
isolation. This can already be done by deleting the corresponding
signature file, but that method can be inconvenient. Add a way to force
IPA module isolation through a new LIBCAMERA_IPA_FORCE_ISOLATION
environment variable.

Signed-off-by: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Reviewed-by: Kieran Bingham <kieran.bingham@ideasonboard.com>
Reviewed-by: Umang Jain <umang.jain@ideasonboard.com>
Reviewed-by: Paul Elder <paul.elder@ideasonboard.com>
This commit is contained in:
Laurent Pinchart 2021-07-12 02:05:33 +03:00
parent a5c81fc945
commit c73170388e
2 changed files with 13 additions and 0 deletions

View file

@ -24,6 +24,11 @@ LIBCAMERA_IPA_CONFIG_PATH
Example value: ``${HOME}/.libcamera/share/ipa:/opt/libcamera/vendor/share/ipa`` Example value: ``${HOME}/.libcamera/share/ipa:/opt/libcamera/vendor/share/ipa``
LIBCAMERA_IPA_FORCE_ISOLATION
When set to a non-empty string, force process isolation of all IPA modules.
Example value: ``1``
LIBCAMERA_IPA_MODULE_PATH LIBCAMERA_IPA_MODULE_PATH
Define custom search locations for IPA modules (`more <IPA module_>`__). Define custom search locations for IPA modules (`more <IPA module_>`__).

View file

@ -276,6 +276,14 @@ IPAModule *IPAManager::module(PipelineHandler *pipe, uint32_t minVersion,
bool IPAManager::isSignatureValid([[maybe_unused]] IPAModule *ipa) const bool IPAManager::isSignatureValid([[maybe_unused]] IPAModule *ipa) const
{ {
#if HAVE_IPA_PUBKEY #if HAVE_IPA_PUBKEY
char *force = utils::secure_getenv("LIBCAMERA_IPA_FORCE_ISOLATION");
if (force && force[0] != '\0') {
LOG(IPAManager, Debug)
<< "Isolation of IPA module " << ipa->path()
<< " forced through environment variable";
return false;
}
File file{ ipa->path() }; File file{ ipa->path() };
if (!file.open(File::ReadOnly)) if (!file.open(File::ReadOnly))
return false; return false;