All of lore.kernel.org
 help / color / mirror / Atom feed
* [meta-security][PATCH] dm-verity-img.bbclass: add DM_VERITY_SETUP_ARGS
@ 2024-11-09 11:31 Grygorii Tertychnyi
  0 siblings, 0 replies; only message in thread
From: Grygorii Tertychnyi @ 2024-11-09 11:31 UTC (permalink / raw)
  To: yocto-patches; +Cc: Grygorii Tertychnyi

Useful to pass additional arguments to veritysetup, for example
'--no-superblock' to make system less vulnerable to certain types of
attacks and data maniputaion on the disk.

Signed-off-by: Grygorii Tertychnyi <grembeter@gmail.com>
---
 classes/dm-verity-img.bbclass | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/classes/dm-verity-img.bbclass b/classes/dm-verity-img.bbclass
index 7f79548353b0..9a3a97ec6c26 100644
--- a/classes/dm-verity-img.bbclass
+++ b/classes/dm-verity-img.bbclass
@@ -46,6 +46,9 @@ DM_VERITY_IMAGE_HASH_BLOCK_SIZE ?= "4096"
 # Should we store the hash data on a separate device/partition?
 DM_VERITY_SEPARATE_HASH ?= "0"
 
+# Additional arguments for veritysetup
+DM_VERITY_SETUP_ARGS ?= ""
+
 # These are arch specific.  We could probably intelligently auto-assign these?
 # Take x86-64 values as defaults. No impact on functionality currently.
 # See SD_GPT_ROOT_X86_64 and SD_GPT_ROOT_X86_64_VERITY in the spec.
@@ -146,6 +149,7 @@ verity_setup() {
     cp -a $INPUT $OUTPUT
 
     SETUP_ARGS=" \
+        ${DM_VERITY_SETUP_ARGS} \
         --data-block-size=${DM_VERITY_IMAGE_DATA_BLOCK_SIZE} \
         --hash-block-size=${DM_VERITY_IMAGE_HASH_BLOCK_SIZE} \
         $HASH_OFFSET format $OUTPUT $OUTPUT_HASH \
-- 
2.39.5



^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2024-11-09 11:29 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-11-09 11:31 [meta-security][PATCH] dm-verity-img.bbclass: add DM_VERITY_SETUP_ARGS Grygorii Tertychnyi

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.