Add dm-verity support to ti-core-initramfs by: - Enabling dm-verity modules and tools (cryptsetup, util-linux-mount) when DM_VERITY_IMAGE is set - Adding do_rootfs[nostamp] and do_image[nostamp] to rebuild initramfs after rootfs verity task completes - Making deploy_verity_hash gracefully handle missing .verity.env file on first pass with bbwarn
Signed-off-by: Atharv Dubey <[email protected]> --- .../machine/include/ti-core-initramfs.inc | 4 +-- .../initramfs/ti-core-initramfs.bbappend | 25 +++++++++++++++++++ 2 files changed, 27 insertions(+), 2 deletions(-) create mode 100644 meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend diff --git a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc index c816f1dc..08da8e80 100644 --- a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc +++ b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc @@ -5,7 +5,7 @@ # TI_CORE_INITRAMFS_ENABLED = "0" # #------------------------------------------------------------------------------ -TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') or bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) else '0'}" +TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') or bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) or d.getVar('DM_VERITY_IMAGE') else '0'}" TI_CORE_INITRAMFS_KERNEL_MODULES ?= "" TI_CORE_INITRAMFS_EXTRA_INSTALL ?= "" @@ -22,4 +22,4 @@ TI_WKS_INITRAMFS ?= "${@ ',initrd=${TI_CORE_INITRAMFS_IMAGE_FILE}' if d.getVar(' IMAGE_BOOT_FILES += "${@ '${TI_CORE_INITRAMFS_IMAGE_FILE}' if d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}" -INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}" +INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}" \ No newline at end of file diff --git a/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend new file mode 100644 index 00000000..25fe775f --- /dev/null +++ b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend @@ -0,0 +1,25 @@ +# Install the essential utils for dm-verity in ti-core-initramfs +TI_CORE_INITRAMFS_EXTRA_INSTALL:append = "${@' initramfs-module-dmverity cryptsetup util-linux-mount' if d.getVar('DM_VERITY_IMAGE') else ''}" + +# Ensure dm-verity.env is updated also when rebuilding DM_VERITY_IMAGE +do_image[nostamp] = "1" +do_rootfs[nostamp] = "1" + +IMAGE_FSTYPES = "${INITRAMFS_FSTYPES}" + +deploy_verity_hash() { + # The .verity.env file is created by the DM_VERITY_IMAGE build (e.g., arago-base-image). + # On the first pass, it won't exist yet because the initramfs is built before the rootfs + # (due to INITRAMFS_IMAGE dependency). The do_rootfs[nostamp] = "1" causes this task + # to re-run after the rootfs is built, at which point the file will exist. + if [ -f ${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env ]; then + install -D -m 0644 \ + ${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env \ + ${IMAGE_ROOTFS}${datadir}/misc/dm-verity.env + else + bbwarn "dm-verity.env not found at ${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env - will retry on rebuild (nostamp)" + fi +} + + +IMAGE_PREPROCESS_COMMAND += "deploy_verity_hash;" -- 2.34.1
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#20423): https://lists.yoctoproject.org/g/meta-ti/message/20423 Mute This Topic: https://lists.yoctoproject.org/mt/121507548/21656 Group Owner: [email protected] Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
