Add dm-verity support to ti-core-initramfs by:
- Enabling dm-verity modules and tools (cryptsetup, util-linux-mount) when 
DM_VERITY_IMAGE is set
- Adding do_rootfs[nostamp] and do_image[nostamp] to rebuild initramfs after 
rootfs verity task completes
- Making deploy_verity_hash gracefully handle missing .verity.env file on first 
pass with bbwarn

Signed-off-by: Atharv Dubey <[email protected]>
---
 .../machine/include/ti-core-initramfs.inc     |  4 +--
 .../initramfs/ti-core-initramfs.bbappend      | 25 +++++++++++++++++++
 2 files changed, 27 insertions(+), 2 deletions(-)
 create mode 100644 
meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend

diff --git a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc 
b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
index c816f1dc..08da8e80 100644
--- a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
+++ b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
@@ -5,7 +5,7 @@
 #   TI_CORE_INITRAMFS_ENABLED = "0"
 #
 #------------------------------------------------------------------------------
-TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if 
d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or 
d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') or 
bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) else '0'}"
+TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if 
d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or 
d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') or 
bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) or 
d.getVar('DM_VERITY_IMAGE') else '0'}"
 
 TI_CORE_INITRAMFS_KERNEL_MODULES ?= ""
 TI_CORE_INITRAMFS_EXTRA_INSTALL ?= ""
@@ -22,4 +22,4 @@ TI_WKS_INITRAMFS ?= "${@ 
',initrd=${TI_CORE_INITRAMFS_IMAGE_FILE}' if d.getVar('
 
 IMAGE_BOOT_FILES += "${@ '${TI_CORE_INITRAMFS_IMAGE_FILE}' if 
d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
 
-INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if 
d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
+INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if 
d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
\ No newline at end of file
diff --git 
a/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
 
b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
new file mode 100644
index 00000000..25fe775f
--- /dev/null
+++ 
b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
@@ -0,0 +1,25 @@
+# Install the essential utils for dm-verity in ti-core-initramfs
+TI_CORE_INITRAMFS_EXTRA_INSTALL:append = "${@' initramfs-module-dmverity 
cryptsetup util-linux-mount' if d.getVar('DM_VERITY_IMAGE') else ''}"
+
+# Ensure dm-verity.env is updated also when rebuilding DM_VERITY_IMAGE
+do_image[nostamp] = "1"
+do_rootfs[nostamp] = "1"
+
+IMAGE_FSTYPES = "${INITRAMFS_FSTYPES}"
+
+deploy_verity_hash() {
+    # The .verity.env file is created by the DM_VERITY_IMAGE build (e.g., 
arago-base-image).
+    # On the first pass, it won't exist yet because the initramfs is built 
before the rootfs
+    # (due to INITRAMFS_IMAGE dependency). The do_rootfs[nostamp] = "1" causes 
this task
+    # to re-run after the rootfs is built, at which point the file will exist.
+    if [ -f 
${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env ]; 
then
+        install -D -m 0644 \
+            
${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env \
+            ${IMAGE_ROOTFS}${datadir}/misc/dm-verity.env
+    else
+        bbwarn "dm-verity.env not found at 
${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env - 
will retry on rebuild (nostamp)"
+    fi
+}
+
+
+IMAGE_PREPROCESS_COMMAND += "deploy_verity_hash;"
-- 
2.34.1

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#20423): 
https://lists.yoctoproject.org/g/meta-ti/message/20423
Mute This Topic: https://lists.yoctoproject.org/mt/121507548/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to