AGL Security Blueprint available online on AGL doc website ↗ has been revamped and completed by Vincent Nieutin / IoT.bzh.
A proposal has been posted online (still on AGL doc website beside the current version: here ↗ ) and is under review by the AGL community.
This proposal includes information of existing Security Blueprint reorganized in a more logical way (bottom to top : hardware to applications,updates) and uses colored sections to highlight and easily identify criticals items.
Some missing parts like SOTA or Secure development have also been added.
[Click here] to download the PDF version of this updated Security Blueprint.
Yocto SDKs or images are currently deployed as monolithic archives.
Projects are more and more complex resulting to larger archives and
consequently, SDKs or target images updates are not efficient at all.
This talk presents a new solution based on incremental updates and binary
packages deployment, which is closer to standard Linux distribution packaging.
This solution offers an easy way to update development environment (SDK)
on the development machine and makes packages management simpler on the target side.
This allows among other to install a minimal set of packages in order to reduce the target filesystem size.
AGL leverages Sytemd for several purposes. Example:
- setup of applications and services (cgroups, namespaces, autostart, permissions)
- use of libsystemd for its programs (event management, dbus interface)
- manage users and user sessions
This presentation explains how using systemd is beneficial for AGL and how the AGL is built to leverage good systemd features.
It reviews the mechanics of systemd integration and how it is used for user management: PAM integration, privacy management.
AGL emphasis a clean separation of applications together and with the underlying system layer. It also provides a mechanism to tune how this is done. This talk presents this aspect. see the presentation
The AGL controller is a new binding that was initially developed to address the lack of AGL mechanism to support policy/access-control in AAAA. The outcome of this effort is a fully generic controller that allows to “glue” many different components directly from a simple JSON configuration file. The resulting service is exposed as a native AGL binder. It is a real Swiss Knife and can be used to many different things for applications or services.AGL Controller is a pure Vanila AGL binding. It can be added transparently to any existing binder through the standard application framework import mechanism. The controller is fully compliant with AGL security model and offers for dynamic APIs the same level of protection that AGL already offers to static APIs.AGL controller is powerful and flexible. It allows developers to simply assemble pre-existing AGL APIs, to expose as AGL native binder a legacy/proprietary technologies. Finally it supports Lua as scripting language to glue everything together. Mixing Native/Script language is supported and a developer may choose to fast track demo in Lua script and later to port all/part in native C/C++ to improve performances.The presentation will show the architecture, the different components and will walk though a set of examples. At the end of the talk attendees should have a clean understanding on how to leverage AGL controller in their own applications.
Download the detailed PDF presentation: [here] (AGL/AMM Dresden/Germany Oct-2017)
This presentation was given at ALS 2017 in Tokyo.
To reduce as much as possible the entry cost for developing automotive applications, AGL should be integrated to IDE and Source Debugger.
Traditionally, installation of an embedded development environment with cross compilation has been difficult and more tortuous that it should. Any developer and especially non system expert, should easily succeed in setting up the AGL development environment on both target & host independently of their preferred OS (Linux, Windows, Mac).
This talk presents a solution that tends to a zeroconf installation of AGL development environment, independently of the chosen target/host.The presented solution allows to locally edit sources with your favorite IDE (i.e. Eclipse, Visual Studio Code, Netbeans...) and either compile locally your application or benefit from a remote server. It also shows how to debug application directly from your preferred editor.
Download the latest presentation (PDF format): [here]
Download older presentations: [here]
- Embedded Linux, case of AGL. Lesson at ENSTA 2019
- Current Market Conditions for Automotive Supply Implies Long Term Support
- Cloud based test infrastructure to enhance software quality assurance (SQA) in AGL application developments
- Current market condition for automotive supply implies Long Term Support
- AGL-Supervision : From AGL Supervisor to platform global data collection
- AGL-µBinder : a fast, secure and seamless option to connect AGL to small ECUs?
- Wlroots : a potential foundation for Next Generation of AGL Wayland Compositor
- L4RE hypervisor consolidating multiple AGL profiles
- Updated overview of AGL signaling
- Cybersecurity for Connected Vehicle with AGL (Automotive Grade Linux)
- Skim down AGL Application Framework to bridge AGL with hard realtime subsystems
- AGL application design
- 4A (Audio Advanced Architecture) Kickstart with AGL/FF
- Moving AGL toward production with the latest test/monitoring tools.
- From Connected Cars to Connected Boats
- Presentation of AGL
- AGL Development Tools, what's new in FF
- AGL & Real Time: Architecture Options
- Véhicule Connecté Cybersécurité et Open Source
- Projet Etudiant ENSIBS - Analyseurs Statiques de code
- Binding API version 3
- X(cross) Development System update - April 2018
- Vehicle 2 Cloud - Telematics and Data collection - April 2018
- AGL 4a and audio roadmap - April 2018
- Vehicle 2 Cloud - Signaling and Data collection - April 2018
- Industrialisation of applications build in embedded environment
- AGL Audio Advanced Architecture
- IoT.bzh and AGL presentation to ENSIBS' students
- Updated AGL Security Blueprint
- Deploy AGL OS and SDK as a Binary Packaging Distribution for Developer
- AGL integration of systemd and user management
- The AGL Swiss Knife for Quick Application Prototyping
- X(cross) Development System - make AGL app development easier
- Vehicle to Cloud: Connecting Cars to Non-Automotive Internet Services
- Low level CAN binding for AGL: a generic way to handle CAN signals
- AGL Development Kit - Features and Roadmap
- Vehicule Signaling Leveraging OpenXC
- AGL Security Framework Review
- Homescreen a New AGL Platform Service