All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] arm/uefi-secureboot: fix race with secureboot keys
@ 2026-08-25 17:43 Jon Mason
  2026-08-26 13:01 ` Jon Mason
  0 siblings, 1 reply; 2+ messages in thread
From: Jon Mason @ 2026-08-25 17:43 UTC (permalink / raw)
  To: meta-arm

gen-sbkeys creates and installs the secure boot signing keys, certificates,
and database used by U-Boot and systemd-boot.  Both recipes require these
files during do_compile, but there was no dependency ensuring that
gen-sbkeys:do_install completed first.

Add an explicit do_compile dependency on gen-sbkeys:do_install for both
U-Boot and systemd-boot to prevent the race, which was causing intermittent
CI failures.

The uki.bbclass also requires the secure boot keys and certificates, but
depends on systemd-boot:do_deploy, which ensures the keys are available before
they are needed.

Issues being tracked in meta-secure-core
https://github.com/Wind-River/meta-secure-core/issues/145
https://github.com/Wind-River/meta-secure-core/issues/146

Signed-off-by: Jon Mason <jon.mason@arm.com>
---
 meta-arm/recipes-bsp/u-boot/u-boot-uefi-secureboot.inc      | 6 ++++--
 .../recipes-core/systemd/systemd-boot-uefi-secureboot.inc   | 3 +++
 2 files changed, 7 insertions(+), 2 deletions(-)

diff --git a/meta-arm/recipes-bsp/u-boot/u-boot-uefi-secureboot.inc b/meta-arm/recipes-bsp/u-boot/u-boot-uefi-secureboot.inc
index af641278e06e..14038503d9b1 100644
--- a/meta-arm/recipes-bsp/u-boot/u-boot-uefi-secureboot.inc
+++ b/meta-arm/recipes-bsp/u-boot/u-boot-uefi-secureboot.inc
@@ -4,12 +4,11 @@ SRC_URI += "file://uefi-secureboot.cfg \
             file://0001-efi_loader-fix-building-with-CONFIG_EFI_VARIABLES_PR.patch \
            "
 
-inherit sbsign
-
 require ${@bb.utils.contains('MACHINE_FEATURES', 'uefi-http-boot', 'u-boot-uefi-http-boot.inc', '', d)}
 require ${@bb.utils.contains('MACHINE_FEATURES', 'uefi-capsule-update', 'u-boot-capsule-update.inc', '', d)}
 
 DEPENDS += 'python3-pyopenssl-native'
+DEPENDS += 'gen-sbkeys'
 
 do_compile:prepend() {
     export CRYPTOGRAPHY_OPENSSL_NO_LEGACY=1
@@ -20,3 +19,6 @@ do_compile:prepend() {
     "${S}"/tools/efivar.py set -i "${S}"/ubootefi.var -n dbx -d "${SBSIGN_KEYS_DIR}"/dbx.esl -t file
     "${S}"/tools/efivar.py print -i "${S}"/ubootefi.var
 }
+
+# Make sure the contents of SBSIGN_KEYS_DIR are actually there
+do_compile[depends] += "gen-sbkeys:do_install"
diff --git a/meta-arm/recipes-core/systemd/systemd-boot-uefi-secureboot.inc b/meta-arm/recipes-core/systemd/systemd-boot-uefi-secureboot.inc
index 9d72dac5cc8a..4ddee880c9e7 100644
--- a/meta-arm/recipes-core/systemd/systemd-boot-uefi-secureboot.inc
+++ b/meta-arm/recipes-core/systemd/systemd-boot-uefi-secureboot.inc
@@ -5,3 +5,6 @@ SBSIGN_TARGET_BINARY = "${B}/src/boot/systemd-boot${EFI_ARCH}.efi"
 do_compile:append() {
     do_sbsign
 }
+
+# Make sure the keys are actually there before trying to sign
+do_compile[depends] += "gen-sbkeys:do_install"
-- 
2.50.1 (Apple Git-155)



^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] arm/uefi-secureboot: fix race with secureboot keys
  2026-08-25 17:43 [PATCH] arm/uefi-secureboot: fix race with secureboot keys Jon Mason
@ 2026-08-26 13:01 ` Jon Mason
  0 siblings, 0 replies; 2+ messages in thread
From: Jon Mason @ 2026-08-26 13:01 UTC (permalink / raw)
  To: meta-arm, Jon Mason


On Tue, 25 Aug 2026 13:43:02 -0400, Jon Mason wrote:
> gen-sbkeys creates and installs the secure boot signing keys, certificates,
> and database used by U-Boot and systemd-boot.  Both recipes require these
> files during do_compile, but there was no dependency ensuring that
> gen-sbkeys:do_install completed first.
> 
> Add an explicit do_compile dependency on gen-sbkeys:do_install for both
> U-Boot and systemd-boot to prevent the race, which was causing intermittent
> CI failures.
> 
> [...]

Applied, thanks!

[1/1] arm/uefi-secureboot: fix race with secureboot keys
      commit: c051ce752398a454e7c77ad60b3d67e3ee465c3b

Best regards,
-- 
Jon Mason <jon.mason@arm.com>


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-26 13:03 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-25 17:43 [PATCH] arm/uefi-secureboot: fix race with secureboot keys Jon Mason
2026-08-26 13:01 ` Jon Mason

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.