All of lore.kernel.org
 help / color / mirror / Atom feed
From: Denys Dmytriyenko <denis@denix.org>
To: reatmon@ti.com
Cc: Shiva Tripathi <s-tripathi1@ti.com>,
	meta-ti@lists.yoctoproject.org, rs@ti.com,
	jcormier@criticallink.com, praneeth@ti.com, kamlesh@ti.com,
	vishalm@ti.com, k-malarvizhi@ti.com, vigneshr@ti.com, afd@ti.com
Subject: Re: [meta-ti][master][PATCH v7 3/3] conf: Enable dynamic security layer for LUKS
Date: Thu, 19 Mar 2026 10:55:27 -0400	[thread overview]
Message-ID: <20260319145527.GP11121@denix.org> (raw)
In-Reply-To: <d9e195a7-5735-410c-be03-734eff2a7497@ti.com>

On Thu, Mar 19, 2026 at 08:59:24AM -0500, Ryan Eatmon via lists.yoctoproject.org wrote:
> 
> 
> On 3/19/2026 5:35 AM, Shiva Tripathi wrote:
> >Register dynamic-layers/security in layer.conf with BBFILES_DYNAMIC
> >for both 'security' and 'tpm-layer' collections to conditionally
> >build LUKS encryption support when meta-security/meta-tpm layers
> >are present.
> >
> >Add meta-security to LAYERRECOMMENDS to document the optional
> >dependency for LUKS functionality.
> >
> >Update ti-core-initramfs.inc to auto-enable initramfs generation
> >when DISTRO_FEATURES contains 'luks'.
> >
> >Signed-off-by: Shiva Tripathi <s-tripathi1@ti.com>
> >---
> >  meta-ti-bsp/conf/layer.conf                            | 5 +++++
> >  meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc | 2 +-
> >  2 files changed, 6 insertions(+), 1 deletion(-)
> >
> >diff --git a/meta-ti-bsp/conf/layer.conf b/meta-ti-bsp/conf/layer.conf
> >index f78da573..36d05b5a 100644
> >--- a/meta-ti-bsp/conf/layer.conf
> >+++ b/meta-ti-bsp/conf/layer.conf
> >@@ -20,10 +20,15 @@ LAYERDEPENDS_meta-ti-bsp = " \
> >  LAYERRECOMMENDS_meta-ti-bsp = " \
> >      openembedded-layer \
> >+    meta-security \
> >  "
> 
> The layer should be same as below:  security and tpm-layer  I was
> just using meta-security as a placeholder.

Yeah, it's quite unfortunate that layer's collection name could be different 
from layer's directory name. Some maintainers keep them the same (e.g. 
meta-ti-bsp), but some make them different (e.g. meta-security -> security 
and meta-tpm -> tpm-layer). It could be rather confusing...


> >  BBFILES_DYNAMIC += " \
> >      openembedded-layer:${LAYERDIR}/dynamic-layers/openembedded-layer/recipes*/*/*.bbappend \
> >+    security:${LAYERDIR}/dynamic-layers/security/recipes*/*/*.bb \
> >+    security:${LAYERDIR}/dynamic-layers/security/recipes*/*/*.bbappend \
> >+    tpm-layer:${LAYERDIR}/dynamic-layers/security/recipes*/*/*.bb \
> >+    tpm-layer:${LAYERDIR}/dynamic-layers/security/recipes*/*/*.bbappend \

Moreover - is there really a need to set up security top level layer here? If 
only TPM tools are needed, then just tpm-layer should be enough, even when it 
comes from within meta-security git repository.

E.g., we set up openembedded-layer here, but that's not meta-openembedded top 
level, but instead meta-oe sub-layer inside meta-openembedded. There are 
sub-layers in there, which are not needed for meta-ti-bsp dependency. Same 
thought goes to tpm-layer.


> >  "
> >  SIGGEN_EXCLUDERECIPES_ABISAFE += " \
> >diff --git a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> >index 9d3cc612..15c05e04 100644
> >--- a/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> >+++ b/meta-ti-bsp/conf/machine/include/ti-core-initramfs.inc
> >@@ -5,7 +5,7 @@
> >  #   TI_CORE_INITRAMFS_ENABLED = "0"
> >  #
> >  #------------------------------------------------------------------------------
> >-TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') else '0'}"
> >+TI_CORE_INITRAMFS_ENABLED ?= "${@ '1' if d.getVar('TI_CORE_INITRAMFS_KERNEL_MODULES') or d.getVar('TI_CORE_INITRAMFS_EXTRA_INSTALL') or bb.utils.contains('DISTRO_FEATURES', 'luks', True, False, d) else '0'}"
> >  TI_CORE_INITRAMFS_KERNEL_MODULES ?= ""
> >  TI_CORE_INITRAMFS_EXTRA_INSTALL ?= ""


  reply	other threads:[~2026-03-19 14:55 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-03-19 10:35 [meta-ti][master][PATCH v7 0/3] Add LUKS encryption with fTPM support Shiva Tripathi
2026-03-19 10:35 ` [meta-ti][master][PATCH v7 1/3] linux-ti-staging: Add LUKS encryption config Shiva Tripathi
2026-03-19 10:35 ` [meta-ti][master][PATCH v7 2/3] initramfs-module-luks-ftpm: Add fTPM support Shiva Tripathi
2026-03-19 10:35 ` [meta-ti][master][PATCH v7 3/3] conf: Enable dynamic security layer for LUKS Shiva Tripathi
2026-03-19 13:59   ` Ryan Eatmon
2026-03-19 14:55     ` Denys Dmytriyenko [this message]
2026-03-19 14:58       ` Ryan Eatmon
2026-03-19 16:35         ` Shiva Tripathi
2026-03-19 10:45 ` [meta-ti][master][PATCH v7 0/3] Add LUKS encryption with fTPM support PRC Automation

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260319145527.GP11121@denix.org \
    --to=denis@denix.org \
    --cc=afd@ti.com \
    --cc=jcormier@criticallink.com \
    --cc=k-malarvizhi@ti.com \
    --cc=kamlesh@ti.com \
    --cc=meta-ti@lists.yoctoproject.org \
    --cc=praneeth@ti.com \
    --cc=reatmon@ti.com \
    --cc=rs@ti.com \
    --cc=s-tripathi1@ti.com \
    --cc=vigneshr@ti.com \
    --cc=vishalm@ti.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.