On Wed, Sep 30, 2026 at 06:29:38PM +0530, Atharv Dubey via 
lists.yoctoproject.org wrote:
> Add dm-verity support to ti-core-initramfs by:
> - Enabling dm-verity modules and tools (cryptsetup, util-linux-mount) when 
> DM_VERITY_IMAGE is set
> - Adding do_rootfs[nostamp] and do_image[nostamp] to rebuild initramfs after 
> rootfs verity task completes
> - Making deploy_verity_hash gracefully handle missing .verity.env file on 
> first pass with bbwarn
> 
> Signed-off-by: Atharv Dubey <[email protected]>
> ---
>  .../machine/include/ti-core-initramfs.inc     |  4 +--
>  .../initramfs/ti-core-initramfs.bbappend      | 25 +++++++++++++++++++
>  2 files changed, 27 insertions(+), 2 deletions(-)
>  create mode 100644 
> meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
> 
> diff --git a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc 
> b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> index c816f1dc..08da8e80 100644
> --- a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> +++ b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> @@ -5,7 +5,7 @@
>  #   TI_CORE_INITRAMFS_ENABLED = "0"
>  #
>  
> #------------------------------------------------------------------------------
> -TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if 
> d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or 
> d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') or 
> bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) else '0'}"
> +TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if 
> d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or 
> d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') or 
> bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) or 
> d.getVar('DM_VERITY_IMAGE') else '0'}"
>  
>  TI_CORE_INITRAMFS_KERNEL_MODULES ?= ""
>  TI_CORE_INITRAMFS_EXTRA_INSTALL ?= ""
> @@ -22,4 +22,4 @@ TI_WKS_INITRAMFS ?= "${@ 
> ',initrd=${TI_CORE_INITRAMFS_IMAGE_FILE}' if d.getVar('
>  
>  IMAGE_BOOT_FILES += "${@ '${TI_CORE_INITRAMFS_IMAGE_FILE}' if 
> d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
>  
> -INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if 
> d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
> +INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if 
> d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
> \ No newline at end of file

You are not changing the code here, but it shows as a diff because you lost 
the newline at the end of file.


> diff --git 
> a/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
>  
> b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
> new file mode 100644
> index 00000000..25fe775f
> --- /dev/null
> +++ 
> b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
> @@ -0,0 +1,25 @@
> +# Install the essential utils for dm-verity in ti-core-initramfs
> +TI_CORE_INITRAMFS_EXTRA_INSTALL:append = "${@' initramfs-module-dmverity 
> cryptsetup util-linux-mount' if d.getVar('DM_VERITY_IMAGE') else ''}"
> +
> +# Ensure dm-verity.env is updated also when rebuilding DM_VERITY_IMAGE
> +do_image[nostamp] = "1"
> +do_rootfs[nostamp] = "1"
> +
> +IMAGE_FSTYPES = "${INITRAMFS_FSTYPES}"
> +
> +deploy_verity_hash() {
> +    # The .verity.env file is created by the DM_VERITY_IMAGE build (e.g., 
> arago-base-image).
> +    # On the first pass, it won't exist yet because the initramfs is built 
> before the rootfs
> +    # (due to INITRAMFS_IMAGE dependency). The do_rootfs[nostamp] = "1" 
> causes this task
> +    # to re-run after the rootfs is built, at which point the file will 
> exist.
> +    if [ -f 
> ${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env 
> ]; then
> +        install -D -m 0644 \
> +            
> ${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env \
> +            ${IMAGE_ROOTFS}${datadir}/misc/dm-verity.env
> +    else
> +        bbwarn "dm-verity.env not found at 
> ${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env - 
> will retry on rebuild (nostamp)"
> +    fi
> +}
> +
> +
> +IMAGE_PREPROCESS_COMMAND += "deploy_verity_hash;"
> -- 
> 2.34.1
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#20427): 
https://lists.yoctoproject.org/g/meta-ti/message/20427
Mute This Topic: https://lists.yoctoproject.org/mt/121507548/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to