On 30/09/26 21:54, Denys Dmytriyenko wrote:
On Wed, Sep 30, 2026 at 06: 29: 38PM +0530, Atharv Dubey via lists. yoctoproject. org wrote: > Add dm-verity support to ti-core-initramfs by: > - Enabling dm-verity modules and tools (cryptsetup, util-linux-mount) when DM_VERITY_IMAGE is set
ZjQcmQRYFpfptBannerStart
This message was sent from outside of Texas Instruments.
Do not click links or open attachments unless you recognize the source of this email and know the content is safe.
Report Suspicious
<https://us-phishalarm-ewt.proofpoint.com/EWT/v1/G3vK!uJdqXRfPtmw7SgZE_JMD3PSdzRdTmnkXYRe2ioxpDfi8vZDP0_QavxK7wTdvuOnYrkFBk0RC1w$>
ZjQcmQRYFpfptBannerEnd
On Wed, Sep 30, 2026 at 06:29:38PM +0530, Atharv Dubey via 
lists.yoctoproject.org wrote:
> Add dm-verity support to ti-core-initramfs by:
> - Enabling dm-verity modules and tools (cryptsetup, util-linux-mount) when 
DM_VERITY_IMAGE is set
> - Adding do_rootfs[nostamp] and do_image[nostamp] to rebuild initramfs after 
rootfs verity task completes
> - Making deploy_verity_hash gracefully handle missing .verity.env file on 
first pass with bbwarn
> > Signed-off-by: Atharv Dubey <[email protected]>
> ---
>  .../machine/include/ti-core-initramfs.inc     |  4 +--
>  .../initramfs/ti-core-initramfs.bbappend      | 25 +++++++++++++++++++
>  2 files changed, 27 insertions(+), 2 deletions(-)
>  create mode 100644 
meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
> > diff --git a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> index c816f1dc..08da8e80 100644
> --- a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> +++ b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> @@ -5,7 +5,7 @@
>  #   TI_CORE_INITRAMFS_ENABLED = "0"
>  #
>  
#------------------------------------------------------------------------------
> -TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if 
d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') 
or bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) else '0'}"
> +TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if 
d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') 
or bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) or 
d.getVar('DM_VERITY_IMAGE') else '0'}"
> > TI_CORE_INITRAMFS_KERNEL_MODULES ?= ""
>  TI_CORE_INITRAMFS_EXTRA_INSTALL ?= ""
> @@ -22,4 +22,4 @@ TI_WKS_INITRAMFS ?= "${@ 
',initrd=${TI_CORE_INITRAMFS_IMAGE_FILE}' if d.getVar('
> > IMAGE_BOOT_FILES += "${@ '${TI_CORE_INITRAMFS_IMAGE_FILE}' if d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}" > > -INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
> +INITRAMFS_IMAGE ?= "${@ '${TI_CORE_INITRAMFS_IMAGE}' if 
d.getVar('TI_CORE_INITRAMFS_ENABLED') == "1" else ''}"
> \ No newline at end of file

You are not changing the code here, but it shows as a diff because you lost
the newline at the end of file.


Will fix this in the nxt revision.



> diff --git 
a/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
 
b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
> new file mode 100644
> index 00000000..25fe775f
> --- /dev/null
> +++ 
b/meta-ti-bsp/dynamic-layers/security-layer/recipes-ti/initramfs/ti-core-initramfs.bbappend
> @@ -0,0 +1,25 @@
> +# Install the essential utils for dm-verity in ti-core-initramfs
> +TI_CORE_INITRAMFS_EXTRA_INSTALL:append = "${@' initramfs-module-dmverity cryptsetup util-linux-mount' if d.getVar('DM_VERITY_IMAGE') else ''}"
> +
> +# Ensure dm-verity.env is updated also when rebuilding DM_VERITY_IMAGE
> +do_image[nostamp] = "1"
> +do_rootfs[nostamp] = "1"
> +
> +IMAGE_FSTYPES = "${INITRAMFS_FSTYPES}"
> +
> +deploy_verity_hash() {
> +    # The .verity.env file is created by the DM_VERITY_IMAGE build (e.g., 
arago-base-image).
> +    # On the first pass, it won't exist yet because the initramfs is built 
before the rootfs
> +    # (due to INITRAMFS_IMAGE dependency). The do_rootfs[nostamp] = "1" 
causes this task
> +    # to re-run after the rootfs is built, at which point the file will 
exist.
> +    if [ -f 
${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env ]; then
> +        install -D -m 0644 \
> +            
${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env \
> +            ${IMAGE_ROOTFS}${datadir}/misc/dm-verity.env
> +    else
> +        bbwarn "dm-verity.env not found at 
${STAGING_VERITY_DIR}/${DM_VERITY_IMAGE}.${DM_VERITY_IMAGE_TYPE}.verity.env - will retry on 
rebuild (nostamp)"
> +    fi
> +}
> +
> +
> +IMAGE_PREPROCESS_COMMAND += "deploy_verity_hash;"
> -- > 2.34.1



-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#20429): 
https://lists.yoctoproject.org/g/meta-ti/message/20429
Mute This Topic: https://lists.yoctoproject.org/mt/121507548/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to