On Wed, Sep 30, 2026 at 06:29:36PM +0530, Atharv Dubey via
lists.yoctoproject.org wrote:
> Add an optional dynamic layer enabling dm-verity block-level integrity
> verification of the root filesystem for TI K3 platforms, using
> meta-security's stock dm-verity mechanism as-is. Requires meta-security
> to be present in bblayers.conf.
>
> dm-verity hashes the rootfs at build time; at boot, a dedicated
> initramfs loads the root hash and the kernel checks every block read
> against it. Set DM_VERITY_IMAGE to enable all the verity-related
> recipes for that image; other images build as usual.
>
> Signed-off-by: Atharv Dubey <[email protected]>
>
> ---
> v4:
> - Use ti-core-initramfs instead of a separate dm-verity initramfs
> - Instead of a DISTRO_FEATURE, just check if DM_VERITY_IMAGE is set
> v3:
> - Disabled the automount rules from udev-aragoconf, so don't need the
> ignorelist for dm-verity
> v2:
> - Replaced hardcoded /dev/mmcblk1p2 with a PARTUUID
> ---
> meta-ti-bsp/conf/layer.conf | 3 +++
> meta-ti-bsp/conf/machine/include/k3.inc | 7 ++++++
> .../conf/include/dm-verity-upstream.inc | 23 +++++++++++++++++++
> .../udev/udev-aragoconf_%.bbappend | 5 ++++
> .../udev/udev-extraconf_%.bbappend | 6 +++++
> meta-ti-bsp/files/wic/k3-verity.wks.in | 5 ++++
> 6 files changed, 49 insertions(+)
> create mode 100644
> meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
> create mode 100644
> meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
> create mode 100644
> meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
> create mode 100644 meta-ti-bsp/files/wic/k3-verity.wks.in
>
> diff --git a/meta-ti-bsp/conf/layer.conf b/meta-ti-bsp/conf/layer.conf
> index 3cc54aa4..aca35cd3 100644
> --- a/meta-ti-bsp/conf/layer.conf
> +++ b/meta-ti-bsp/conf/layer.conf
> @@ -20,12 +20,15 @@ LAYERDEPENDS_meta-ti-bsp = " \
> LAYERRECOMMENDS_meta-ti-bsp = " \
> openembedded-layer \
> tpm-layer \
> + security \
> "
>
> BBFILES_DYNAMIC += " \
>
> openembedded-layer:${LAYERDIR}/dynamic-layers/openembedded-layer/recipes*/*/*.bbappend
> \
> tpm-layer:${LAYERDIR}/dynamic-layers/tpm-layer/recipes*/*/*.bb \
> tpm-layer:${LAYERDIR}/dynamic-layers/tpm-layer/recipes*/*/*.bbappend \
> + security:${LAYERDIR}/dynamic-layers/security-layer/recipes*/*/*.bb \
> + security:${LAYERDIR}/dynamic-layers/security-layer/recipes*/*/*.bbappend
> \
> "
>
> SIGGEN_EXCLUDERECIPES_ABISAFE += " \
> diff --git a/meta-ti-bsp/conf/machine/include/k3.inc
> b/meta-ti-bsp/conf/machine/include/k3.inc
> index 2ebbfb9e..f19db45f 100644
> --- a/meta-ti-bsp/conf/machine/include/k3.inc
> +++ b/meta-ti-bsp/conf/machine/include/k3.inc
> @@ -64,3 +64,10 @@ FALCON_INCLUDE = ""
> FALCON_INCLUDE:ti-falcon = "conf/machine/include/ti-falcon.inc"
>
> require ${FALCON_INCLUDE}
> +
> +# dm-verity protects the rootfs listed in DM_VERITY_IMAGE; see
> dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc for what
> that turns on.
> +DM_VERITY_IMAGE ??= ""
> +
> +DM_VERITY_UPSTREAM_INCLUDE =
> "${@'dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc' if
> d.getVar('DM_VERITY_IMAGE') else ''}"
> +
> +require ${DM_VERITY_UPSTREAM_INCLUDE}
> diff --git
> a/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
>
> b/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
> new file mode 100644
> index 00000000..3ff2b7d6
> --- /dev/null
> +++
> b/meta-ti-bsp/dynamic-layers/security-layer/conf/include/dm-verity-upstream.inc
> @@ -0,0 +1,23 @@
> +# Enables dm-verity to check the rootfs for tampering on TI K3 boards.
> +DM_VERITY_IMAGE_TYPE = "ext4"
> +IMAGE_CLASSES += "dm-verity-img"
> +
> +# ti-core-initramfs.bbappend already wires the initramfs into the boot
> partition once dm-verity is enabled, so we don't need to do it here.
> +
> +# Derive the root partition's UUID from MACHINE so everyone computes the
> same one.
> +python () {
> + import uuid
> +
> + if not d.getVar('DM_VERITY_ROOT_PARTUUID'):
> + d.setVar('DM_VERITY_ROOT_PARTUUID',
> + str(uuid.uuid5(uuid.NAMESPACE_DNS, 'dm-verity-root-%s' %
> d.getVar('MACHINE'))))
> +}
Should these 2 anonymous python functions be combined and the above code go
behind the check below? Is DM_VERITY_ROOT_PARTUUID needed outside of the
DM_VERITY_IMAGE image?
> +
> +python () {
> + if d.getVar('PN') != d.getVar('DM_VERITY_IMAGE'):
> + return
> +
> + d.setVar('WKS_FILE', 'k3-verity.wks.in')
> + d.appendVar('EXTRA_IMAGE_FEATURES', ' read-only-rootfs')
> + d.appendVar('WICVARS', ' DM_VERITY_IMAGE DM_VERITY_IMAGE_TYPE
> IMAGE_NAME_SUFFIX IMGDEPLOYDIR DM_VERITY_ROOT_PARTUUID')
> +}
> diff --git
> a/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
>
> b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
> new file mode 100644
> index 00000000..e5f6c1b2
> --- /dev/null
> +++
> b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-aragoconf_%.bbappend
> @@ -0,0 +1,5 @@
> +do_install:append() {
> + if ${@'true' if d.getVar('DM_VERITY_IMAGE') else 'false'}; then
> + : > ${D}${libdir}/udev/rules.d/50-arago.rules
Why not simply remove the file?
> + fi
> +}
> diff --git
> a/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
>
> b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
> new file mode 100644
> index 00000000..a14e21ea
> --- /dev/null
> +++
> b/meta-ti-bsp/dynamic-layers/security-layer/recipes-core/udev/udev-extraconf_%.bbappend
> @@ -0,0 +1,6 @@
> +# Nothing should ever get auto-mounted under dm-verity, so just kill the
> automounter.
> +do_install:append() {
> + if ${@'true' if d.getVar('DM_VERITY_IMAGE') else 'false'}; then
> + : > ${D}${sysconfdir}/udev/rules.d/automount.rules
Same question as above.
> + fi
> +}
> diff --git a/meta-ti-bsp/files/wic/k3-verity.wks.in
> b/meta-ti-bsp/files/wic/k3-verity.wks.in
> new file mode 100644
> index 00000000..62ae0ec1
> --- /dev/null
> +++ b/meta-ti-bsp/files/wic/k3-verity.wks.in
> @@ -0,0 +1,5 @@
> +# Disk layout for a board that boots with dm-verity enabled.
> +
> +bootloader --timeout=3 --append="rootfstype=ext4
> root=PARTUUID=${DM_VERITY_ROOT_PARTUUID} ${TI_WKS_BOOTLOADER_APPEND}"
> +part --source bootimg-efi
> --sourceparams="loader=${EFI_PROVIDER}${TI_WKS_INITRAMFS}" --fstype=vfat
> --label boot --active --align 1024 --use-uuid --fixed-size 128M
> +part / --source rawcopy
> --sourceparams="file=${IMGDEPLOYDIR}/${DM_VERITY_IMAGE}-${MACHINE}${IMAGE_NAME_SUFFIX}.${DM_VERITY_IMAGE_TYPE}.verity"
> --align 1024 --uuid ${DM_VERITY_ROOT_PARTUUID}
> --
> 2.34.1
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#20426):
https://lists.yoctoproject.org/g/meta-ti/message/20426
Mute This Topic: https://lists.yoctoproject.org/mt/121507536/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-